An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
{ "severity": "High", "cpes": [ "cpe:2.3:a:openresty:lua-nginx-module:*:*:*:*:*:*:*:*" ] }