Openlitespeed

Litespeedtech · 13 CVEs

CVE-2026-104474
MEDIUM

OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update

Oct 3, 2026

CVE-2026-31386
HIGH

OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An…

Mar 16, 2026

CVE-2025-54939
HIGH

LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

Aug 1, 2025

CVE-2024-31617
MEDIUM

OpenLiteSpeed before 1.8.1 mishandles chunked encoding.

May 22, 2024

CVE-2023-40518
HIGH

LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.

Aug 14, 2023

CVE-2022-0074
HIGH

Privilege Escalation in OpenLiteSpeed Web Server

Oct 27, 2022

CVE-2022-0073
HIGH

Authenticated Remote Code Execution in OpenLiteSpeed Web Server

Oct 27, 2022

CVE-2022-0072
MEDIUM

Directory Traversal in OpenLiteSpeed Web Server

Oct 27, 2022

CVE-2021-26758
HIGH

Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root ter…

Apr 7, 2021

CVE-2020-5519
CRITICAL

The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Serve…

Jan 6, 2020

CVE-2018-19792
MEDIUM

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow…

Dec 3, 2018

CVE-2018-19791
MEDIUM

The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing…

Dec 3, 2018

CVE-2015-3890
HIGH

Use-after-free vulnerability in Open Litespeed before 1.3.10.

Sep 20, 2017

Showing 1 to 13 of 13 CVEs