Direct Vulnerabilities

Known vulnerabilities in the mod_lua package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Incorrect Implementation of Authentication Algorithm

*
  • L
Deployment of Wrong Handler

*
  • L
Improper Cross-boundary Removal of Sensitive Data

*
  • L
Out-of-bounds Write

*
  • M
Server-Side Request Forgery (SSRF)

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
HTTP Request Smuggling

*
  • H
Authentication Bypass

*
  • M
Files or Directories Accessible to External Parties

*
  • H
Out-of-bounds Write

*
  • H
NULL Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • H
NULL Pointer Dereference

*
  • M
Path Equivalence

*
  • M
Integer Overflow or Wraparound

*
  • L
Expired Pointer Dereference

<0:2.4.63-13.el10_2.6
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:2.4.63-13.el10_2.4
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

<0:2.4.63-13.el10_2.4
  • M
Buffer Overflow

<0:2.4.63-13.el10_2.4
  • H
Out-of-bounds Read

<0:2.4.63-13.el10_2.4
  • H
Buffer Overflow

<0:2.4.63-13.el10_2.4
  • H
Buffer Overflow

<0:2.4.63-13.el10_2.4
  • M
Directory Traversal

<0:2.4.63-13.el10_2.4
  • M
Incorrect Privilege Assignment

<0:2.4.63-13.el10_2.4
  • M
Cross-site Scripting (XSS)

*
  • M
Buffer Underflow

<0:2.4.63-13.el10_2.4
  • M
CRLF Injection

*
  • L
NULL Pointer Dereference

<0:2.4.63-13.el10_2.4
  • M
Information Exposure

<0:2.4.63-13.el10_2.4
  • M
Buffer Over-read

<0:2.4.63-13.el10_2.1
  • M
NULL Pointer Dereference

<0:2.4.63-13.el10_2.1
  • M
Out-of-bounds Read

<0:2.4.63-13.el10_2.1
  • M
Improper Null Termination

<0:2.4.63-13.el10_2.1
  • M
External Control of File Name or Path

<0:2.4.63-13.el10_2.4
  • H
Out-of-bounds Write

<0:2.4.63-13.el10_2.1
  • H
Information Exposure

<0:2.4.63-4.el10_1.3
  • M
Authentication Bypass by Primary Weakness

<0:2.4.63-4.el10_1.3
  • M
Improper Neutralization

<0:2.4.63-4.el10_1.3
  • M
Resource Exhaustion

*
  • M
Server-Side Request Forgery (SSRF)

*
  • M
CRLF Injection

<0:2.4.63-13.el10_2.4
  • M
Improper Access Control

<0:2.4.63-1.el10_0.2
  • M
Improper Output Neutralization for Logs

<0:2.4.63-1.el10_0.2
  • M
HTTP Request Smuggling

<0:2.4.63-1.el10_0.2