Logo
componentlua-http
Name
lua-http
Version
0.4-0
Type
library
Description
-
Licenses
MIT
PURL
-
CPE
cpe:2.3:a:daurnimator:lua-http:0.4:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
2025.02.x
0.4-0

Patches#


#
Title
Author
Resolve
1
http/h1_stream: handle EOF when `body_read_type==length`
daurnimator <quae@daurnimator.com>
CVE-2023-4540

Vulnerabilities#


Name
Analysis
Description
Patched
Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop. This issue affects lua-http: all versions before commit ddab283.