AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-39702

MEDIUM · CVSS 5.9 EPSS 0.56%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-07-23 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.9. It affects GitHub. It may lead to a denial-of-service condition.

CVE
CVE-2024-39702
Severity
MEDIUM
CVSS
5.9
EPSS
0.56%
GitHub

Original NVD Description

In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could cause excessive resource usage during proxy operations via crafted requests, potentially leading to a denial of service with relatively few incoming requests. This vulnerability only exists in the OpenResty fork in the openresty/luajit2 GitHub repository. The LuaJIT/LuaJIT repository. is unaffected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)