openresty records
8 published records for vendor openresty.
Researcher profile
- Entered KEV
- 1 · 12.5%
- Weaponized
- 1 · 12.5%
- Pre-auth RCE
- 0
- With a fix record
- 75%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')2
- CWE-193 Off-by-one Error1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-787 Out-of-bounds Write1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
46Plan | CVE-2021-23017Proof of concept | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cauf5 · nginx · CWE-193 | High7.7 | — | 53.5% | Jun 1, 2021 |
43Plan | CVE-2018-9230No exploit | In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore paopenresty · openresty · CWE-89 | Critical9.8 | — | 13.2% | Apr 2, 2018 |
31Monitor | CVE-2020-11724No exploit | An issue was discovered in OpenResty before 1.15.8.4.openresty · openresty · CWE-444 | High7.5 | — | 2.6% | Apr 12, 2020 |
30Monitor | CVE-2024-33452No exploit | An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD reopenresty · lua-nginx-module · CWE-444 | High7.7 | — | 0.8% | Apr 22, 2025 |
30Monitor | CVE-2026-55233No exploit | OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstreamopenresty · openresty · CWE-787 | High7.5 | — | 0.5% | Jul 10, 2026 |
23Monitor | CVE-2024-39702No exploit | In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denopenresty · openresty · CWE-407 | Medium5.9 | — | 0.6% | Jul 23, 2024 |
21Monitor | CVE-2020-36309No exploit | ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate openresty · lua-nginx-module | Medium5.3 | — | 1.4% | Apr 6, 2021 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2021-2301746Plan
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cau
HighCVSS 7.7Proof of conceptEPSS 53%f5 · nginxJun 1, 2021
- CVE-2018-923043Plan
In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore pa
CriticalCVSS 9.8No exploitEPSS 13%openresty · openrestyApr 2, 2018
- CVE-2020-1172431Monitor
An issue was discovered in OpenResty before 1.15.8.4.
HighCVSS 7.5No exploitEPSS 3%openresty · openrestyApr 12, 2020
- CVE-2024-3345230Monitor
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD re
HighCVSS 7.7No exploitEPSS 1%openresty · lua-nginx-moduleApr 22, 2025
- CVE-2026-5523330Monitor
OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream
HighCVSS 7.5No exploitEPSS 0%openresty · openrestyJul 10, 2026
- CVE-2024-3970223Monitor
In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Den
MediumCVSS 5.9No exploitEPSS 1%openresty · openrestyJul 23, 2024
- CVE-2020-3630921Monitor
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate
MediumCVSS 5.3No exploitEPSS 1%openresty · lua-nginx-moduleApr 6, 2021