← Back

Openlitespeed

openlitespeed

Vendor: Litespeedtech • 11 CVEs

CVEs (11)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Litespeedtech
4Litespeed Web Adc
Litespeed Web ServerLsquic+1 more
Aug 27, 2025
Aug 1, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
1Litespeedtech
1Openlitespeed
Jun 5, 2025
May 22, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
1Litespeedtech
1Openlitespeed
Nov 21, 2024
Aug 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
1Litespeedtech
1Openlitespeed
Nov 21, 2024
Oct 27, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1.6.15 before 1.7.16.1.
1Litespeedtech
1Openlitespeed
Nov 21, 2024
Oct 27, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 versions before 1.7.16.1.
1Litespeedtech
1Openlitespeed
Nov 21, 2024
Oct 27, 2022
N/A· v4
5.8 MEDIUM· v3
N/A· v2
Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20....Show more
Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20.1, from 1.7.0 before 1.7.16.1Show less
1Litespeedtech
1Openlitespeed
Nov 21, 2024
Apr 7, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the host system.
1Litespeedtech
1Openlitespeed
Nov 21, 2024
Jan 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.
1Litespeedtech
1Openlitespeed
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed pro...Show more
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other impact by creating a symlink through which the openlitespeed program can be invoked with a long command name (involving ../ characters), which is mishandled in the LshttpdMain::getServerRootFromExecutablePath function.Show less
1Litespeedtech
1Openlitespeed
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size by requesting the entire response body repeatedly, as demons...Show more
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size by requesting the entire response body repeatedly, as demonstrated by an HTTP Range header value beginning with the "bytes=0-,0-" substring.Show less
1Litespeedtech
1Openlitespeed
May 13, 2026
Sep 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Use-after-free vulnerability in Open Litespeed before 1.3.10.