An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn
https://lists.debian.org/debian-lts-announce/2025/06/msg00026.html