Openlitespeed
Litespeedtech · 13 CVEs
OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update
Oct 3, 2026
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An…
Mar 16, 2026
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
Aug 1, 2025
OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
May 22, 2024
LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
Aug 14, 2023
Privilege Escalation in OpenLiteSpeed Web Server
Oct 27, 2022
Authenticated Remote Code Execution in OpenLiteSpeed Web Server
Oct 27, 2022
Directory Traversal in OpenLiteSpeed Web Server
Oct 27, 2022
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root ter…
Apr 7, 2021
The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Serve…
Jan 6, 2020
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow…
Dec 3, 2018
The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing…
Dec 3, 2018
Use-after-free vulnerability in Open Litespeed before 1.3.10.
Sep 20, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-104474 | OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update | MEDIUM | 0.08% | Oct 3, 2026 |
| CVE-2026-31386 | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by… | HIGH | 2.13% | Mar 16, 2026 |
| CVE-2025-54939 | LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak. | HIGH | 0.80% | Aug 1, 2025 |
| CVE-2024-31617 | OpenLiteSpeed before 1.8.1 mishandles chunked encoding. | MEDIUM | 0.44% | May 22, 2024 |
| CVE-2023-40518 | LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers. | HIGH | 0.65% | Aug 14, 2023 |
| CVE-2022-0074 | Privilege Escalation in OpenLiteSpeed Web Server | HIGH | 1.26% | Oct 27, 2022 |
| CVE-2022-0073 | Authenticated Remote Code Execution in OpenLiteSpeed Web Server | HIGH | 9.21% | Oct 27, 2022 |
| CVE-2022-0072 | Directory Traversal in OpenLiteSpeed Web Server | MEDIUM | 0.99% | Oct 27, 2022 |
| CVE-2021-26758 | Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the… | HIGH | 2.71% | Apr 7, 2021 |
| CVE-2020-5519 | The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen. | CRITICAL | 1.20% | Jan 6, 2020 |
| CVE-2018-19792 | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow) or possibly have unspecified other imp… | MEDIUM | 0.43% | Dec 3, 2018 |
| CVE-2018-19791 | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing an attacker to amplify the response size… | MEDIUM | 1.24% | Dec 3, 2018 |
| CVE-2015-3890 | Use-after-free vulnerability in Open Litespeed before 1.3.10. | HIGH | 1.06% | Sep 20, 2017 |
Showing 1 to 13 of 13 CVEs