Junglewise Threat Intelligence

CVE-2026-55233: OpenResty out-of-bounds write in PROXY protocol v2 implementation

CVE-2026-55233 · Severity: high · CVSS 7.5 · Published 2026-07-10

Executive brief

OpenResty is a high-performance web platform used to manage and route web traffic. A security flaw in how it handles specific connection headers (PROXY protocol v2) can allow an attacker to crash the service. This results in a denial of service, potentially taking websites or applications offline, though it does not directly expose customer data.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in OpenResty's implementation of the PROXY protocol v2 for upstream connections. When the platform is configured to send these headers, a flaw in the stream proxy protocol v2 patch allows header construction to exceed the allocated buffer size. This memory corruption causes the worker process to crash. The attack can be triggered over the network without authentication, but only impacts systems where PROXY protocol v2 is explicitly enabled for upstream servers. The issue is resolved in version 1.29.2.5.

Affected products

  • OpenResty OpenResty >= 1.27.1.1, < 1.29.2.5

Timeline

  • 2026-06-17: advisory: GitHub Security Advisory published
  • 2026-07-10: disclosed: CVE published to NVD
  • 2026-07-10: patched: Fix confirmed in version 1.29.2.5

References