An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
{ "cpes": [ "cpe:2.3:a:openresty:lua-nginx-module:*:*:*:*:*:*:*:*" ], "severity": "High" }