CVE-2024-33452
Published Apr 22, 2025
·Updated
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
Affected Software
2 affected components
OpenResty lua-nginx-module<=0.10.26
OpenResty lua-nginx-module<=0.10.26
Event History
Apr 22, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33452?
CVE-2024-33452 is considered a critical vulnerability due to its potential for HTTP request smuggling.
2
How do I fix CVE-2024-33452?
To mitigate CVE-2024-33452, upgrade the OpenResty lua-nginx-module to version 0.10.27 or later.
3
What causes CVE-2024-33452?
CVE-2024-33452 is caused by improper handling of crafted HEAD requests in the OpenResty lua-nginx-module.
4
Can CVE-2024-33452 be exploited remotely?
Yes, CVE-2024-33452 can be exploited remotely by an attacker through specially crafted HTTP requests.
5
Which versions of OpenResty lua-nginx-module are vulnerable to CVE-2024-33452?
OpenResty lua-nginx-module versions up to and including 0.10.26 are vulnerable to CVE-2024-33452.