ngxhttplua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-36309.json"