High severity7.7NVD Advisory· Published Apr 22, 2025· Updated Jun 17, 2026
CVE-2024-33452
CVE-2024-33452
Description
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:openresty:lua-nginx-module:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:openresty:lua-nginx-module:*:*:*:*:*:*:*:*range: <=0.10.26
- (no CPE)
- (no CPE)range: <=0.10.26
Patches
Vulnerability mechanics
References
3- portswigger.net/research/http-desync-attacks-request-smuggling-rebornnvdExploitThird Party Advisory
- www.benasin.space/2025/03/18/OpenResty-lua-nginx-module-v0-10-26-HTTP-Request-Smuggling-in-HEAD-requests/nvdExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2025/06/msg00026.htmlnvd
News mentions
0No linked articles in our index yet.