CVE-2024-33452 Information
Apr 23, 2025
cve
Description
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
Reference
https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn https://www.benasin.space/2025/03/18/OpenResty-lua-nginx-module-v0-10-26-HTTP-Request-Smuggling-in-HEAD-requests/
Share on: