Skip to content
Noroxi

openresty records

8 published records for vendor openresty.

Researcher profile

Entered KEV
1 · 12.5%
Weaponized
1 · 12.5%
Pre-auth RCE
0
With a fix record
75%
Median publish → KEV
0 days

All records

8 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cau

    HighCVSS 7.7Proof of conceptEPSS 53%

    f5 · nginxJun 1, 2021

  • In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore pa

    CriticalCVSS 9.8No exploitEPSS 13%

    openresty · openrestyApr 2, 2018

  • An issue was discovered in OpenResty before 1.15.8.4.

    HighCVSS 7.5No exploitEPSS 3%

    openresty · openrestyApr 12, 2020

  • An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD re

    HighCVSS 7.7No exploitEPSS 1%

    openresty · lua-nginx-moduleApr 22, 2025

  • OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream

    HighCVSS 7.5No exploitEPSS 0%

    openresty · openrestyJul 10, 2026

  • In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Den

    MediumCVSS 5.9No exploitEPSS 1%

    openresty · openrestyJul 23, 2024

  • ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate

    MediumCVSS 5.3No exploitEPSS 1%

    openresty · lua-nginx-moduleApr 6, 2021