An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
{
"severity": "High",
"cpes": [
"cpe:2.3:a:openresty:lua-nginx-module:*:*:*:*:*:*:*:*"
]
}