CVE-2026-55233
Last modified
CVE-2026-55233 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY protocol v2 implementation. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY protocol v2 implementation. When OpenResty is configured to send PROXY protocol version 2 headers to upstream servers, constructing the header in the stream proxy protocol v2 patch can write beyond the bounds of the allocated buffer, causing the worker process to crash and resulting in a denial of service. Only configurations that explicitly enable PROXY protocol v2 for upstream connections are impacted. This issue is fixed in version 1.29.2.5.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openresty | Openresty | >= 1.29.2.1, < 1.29.2.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-55233?
How severe is CVE-2026-55233?
How do I fix CVE-2026-55233?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55225Strimzi provides a way to run an Apache Kafka cluster on Kub…8
- CVE-2026-55226Strimzi provides a way to run an Apache Kafka cluster on Kub…5.4
- CVE-2026-55227Weblate is a web-based localization tool. In versions prior …4.3
- CVE-2026-55228Weblate is a web-based continuous localization platform used…8.1
- CVE-2026-55229Gotenberg is a Docker-powered stateless API for PDF files. P…7.5
- CVE-2026-5523The Divi Form Builder plugin for WordPress is vulnerable to …8.8
- CVE-2026-55234Wekan is open source kanban built with Meteor. Prior to 9.37…8.5
- CVE-2026-55235langgraph-api implements the LangGraph API for rapid develop…5.9
- CVE-2026-55236langgraph-api implements the LangGraph API for rapid develop…5.9
- CVE-2026-55237AutoGPT is a workflow automation platform for creating, depl…8.8
- CVE-2026-55238xrdp is an open source RDP server. Versions 0.10.6 and prior…5.3
- CVE-2026-5524The Divi Form Builder plugin for WordPress is vulnerable to …9.8
Are you affected by CVE-2026-55233?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
