CVE-2024-33452: Openresty Lua-Nginx-Module

High severity, CVSS 7.7. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.

Affected products

  • Openresty Lua-Nginx-Module: up to and including 0.10.26

Published 2025-04-22. Last modified 2026-06-17.