openresty is vulnerable to Out-of-bounds Write
75
High Risk
OpenResty's stream module includes an upstream PROXY protocol v2 patch that builds a binary protocol header before forwarding a connection to an upstream server. When a deployment is configured to emit PROXY protocol v2 to upstreams, the header serialization advances a write pointer through address-family and Type-Length-Value fields without fully validating the remaining space in the preallocated buffer. This lets the routine write past the buffer boundary, which results in a denial of service. The fix adds bounds enforcement so header bytes are only written when sufficient buffer space remains.
You are affected if you are running a version in the vulnerable range and your configuration explicitly enables PROXY protocol v2 for upstream connections.
openresty is vulnerable to Out-of-bounds Write in versions 1.29.2.1 - 1.29.2.4.
Upgrade the openresty/openresty library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant