CVE-2026-55233Patch(openresty / openresty)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openresty openresty systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY protocol v2 implementation. When OpenResty is configured to send PROXY protocol version 2 headers to upstream servers, constructing the header in the stream proxy protocol v2 patch can write beyond the bounds of the allocated buffer, causing the worker process to crash and resulting in a denial of service. Only configurations that explicitly enable PROXY protocol v2 for upstream connections are impacted. This issue is fixed in version 1.29.2.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openresty

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openresty

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-11: 1Mentions · 2026-07-15: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-15: 107-1107-15
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-111
Patch1
2026-07-151
Disclosure1
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 OpenResty, Out-of-Bounds Write (CWE-787), #CVE-2026-55233 (HIGH) -DC-Jul2026-960 https://dailycve.com/openresty-out-of-bounds-write-cwe-787-cve-2026-55233-high-dc-jul2026-960/

    Post summary

    The statement announces the high‑severity CVE‑2026‑55233 for OpenResty, highlighting an out‑of‑bounds write vulnerability.

    0000040
    219 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-55233 - DoS via OOB write in #OpenResty PROXY protocol v2. CVSS 7.5. Workers crash when sending #PROXY headers. Update to 1.29.2.5 immediately. #CVEAlert #OpenResty #infosec #devops #devsecops #sysadmin #git #gitlab #docker #linux https://www.valtersit.com/cve/CVE-2026-55233/

    Post summary

    The message warns of a DoS vulnerability in OpenResty, provides technical details, and urges an immediate update to version 1.29.2.5 to mitigate the issue.

    0000069
    978 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenrestyopenresty---

Explore more