An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
{
"cpes": [
"cpe:2.3:a:openresty:lua-nginx-module:*:*:*:*:*:*:*:*"
],
"severity": "High"
}