In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1,...
Moderate severity
Unreviewed
Published
Jul 23, 2024
to the GitHub Advisory Database
•
Updated Nov 26, 2024
Description
Published by the National Vulnerability Database
Jul 23, 2024
Published to the GitHub Advisory Database
Jul 23, 2024
Last updated
Nov 26, 2024
In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could cause excessive resource usage during proxy operations via crafted requests, potentially leading to a denial of service with relatively few incoming requests. This vulnerability only exists in the OpenResty fork in the openresty/luajit2 GitHub repository. The LuaJIT/LuaJIT epository. is unaffected/
References