An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
https://github.com/seta-hoangbui/CVE_search
https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn
https://lists.debian.org/debian-lts-announce/2025/06/msg00026.html