Known Vulnerabilities for Lua-nginx-module by Openresty
Listed below are 1 of the newest known vulnerabilities associated with "Lua-nginx-module" by "Openresty".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-90439 json | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versio... | Not Provided | 2026-09-15 | 2026-09-16 |
| CVE-2026-78689 json | Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through ... | Not Provided | 2026-09-02 | 2026-09-03 |
| CVE-2026-60065 json | When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_mod... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-60005 json | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unna... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-56434 json | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when t... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-55149 json | Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/c... | Not Provided | 2026-09-15 | 2026-09-17 |
| CVE-2026-42945 json | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when ... | Not Provided | 2026-05-13 | 2026-09-10 |
| CVE-2026-42530 json | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP... | Not Provided | 2026-06-17 | 2026-07-16 |
| CVE-2026-32647 json | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to tri... | Not Provided | 2026-03-24 | 2026-07-15 |
| CVE-2026-27784 json | The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an at... | Not Provided | 2026-03-24 | 2026-07-15 |