← Back

Lua Nginx Module

lua-nginx-module

Vendor: Openresty • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openresty
1Lua Nginx Module
Jun 17, 2026
Apr 22, 2025
N/A· v4
7.7 HIGH· v3
N/A· v2
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
1Openresty
1Lua Nginx Module
Jun 17, 2026
Apr 6, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.