Openresty
This hub aggregates every CVE we track for Openresty, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
2
Critical
4
High
1
In CISA KEV
Severity distribution
HIGH4CRITICAL2LOW1MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
2024-092026-08
Latest CVEs
The 8 most recently published vulnerabilities affecting Openresty.
- CVE-2026-55233OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream7.5
- CVE-2024-39702In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could cause excessiv...5.9
- CVE-2024-399111Panel SQL injection10.0
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.KEV7.5
- BDU:2021-05751Уязвимость функции ngx_memcpy веб-сервера OpenResty, связанная с переполнением буфера, позволяющая нарушителю вызвать отказ в обслуживании3.9
- CVE-2021-23017A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process c...7.7
- CVE-2020-11724An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.7.5
- CVE-2018-9230In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remo...9.8
Product normalization is registry-driven with AI assist and human review. How it works