{"id":13159,"date":"2025-08-18T15:56:42","date_gmt":"2025-08-18T19:56:42","guid":{"rendered":"https:\/\/blog.litespeedtech.com\/?p=13159"},"modified":"2025-08-18T15:56:42","modified_gmt":"2025-08-18T19:56:42","slug":"litespeed-security-update","status":"publish","type":"post","link":"https:\/\/lswp.store\/index.php\/2025\/08\/18\/litespeed-security-update\/","title":{"rendered":"LiteSpeed Security Update"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-13161\" src=\"https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/lsquic-vuln2-1.png\" alt=\"LiteSpeed Security Update\" width=\"1000\" height=\"500\" srcset=\"https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/lsquic-vuln2-1.png 1000w, https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/lsquic-vuln2-1-300x150.png 300w, https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/lsquic-vuln2-1-768x384.png 768w, https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/lsquic-vuln2-1-600x300.png 600w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/p>\n<p>We have a security update for LiteSpeed\u2019s QUIC and HTTP\/3 Library (LSQUIC), and all three LiteSpeed server products. Recently we were made aware of a vulnerability affecting LSQUIC. We patched this vulnerability in v4.3.1.<\/p>\n<p>Please update to the latest versions of LSQUIC and all LiteSpeed server products.<\/p>\n<p>This Allocation of Resources Without Limits or Throttling vulnerability, reported by\u00a0<a href=\"https:\/\/www.imperva.com\/blog\/quic-leak-cve-2025-54939-new-high-risk-pre-handshake-remote-denial-of-service-in-lsquic-quic-implementation\/\">Yohann Sillam from Imperva Offensive Team<\/a>, has been assigned <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-54939\">CVE-2025-54939<\/a>.<\/p>\n<h2>Impact<\/h2>\n<p>UDP packets, crafted in a particular way and sent to the HTTP\/QUIC service port, can cause an unbounded memory leak. This has the potential to cause the process or the server to run out of memory, eventually leading to a Denial of Service.<\/p>\n<p>This vulnerability in the LSQUIC Library affects all server products and may be easily exploited.<\/p>\n<h2>Actions<\/h2>\n<p>We strongly recommend that those using the QUIC and HTTP\/3 library upgrade to LSQUIC version 4.3.1 or higher to patch this vulnerability.<\/p>\n<p>Additionally, those who are using LiteSpeed server products, should upgrade to the following versions of these products immediately:<\/p>\n<ul>\n<li>LiteSpeed Web Server (LSWS) v6.3.4 or higher<\/li>\n<li>LiteSpeed Web ADC (LSADC) v3.3.1 or higher<\/li>\n<li>OpenLiteSpeed (OLS) v1.8.4 or higher<\/li>\n<\/ul>\n<p>If you cannot upgrade your server at this time, you can disable HTTP\/3 to avoid this vulnerability.<\/p>\n<h2>Timeline<\/h2>\n<ul>\n<li><strong>July 15, 2025<\/strong>: We were alerted to the issue.<\/li>\n<li><strong>July 18, 2025<\/strong>: Patch was added to our internal repo to be included in all subsequent builds of our commercial server products<\/li>\n<li><strong>August 1, 2025<\/strong>: Released LSWS v6.3.4 and OLS v1.8.4<\/li>\n<li><strong>August 4, 2025<\/strong>: Released LSADC v3.3.1<\/li>\n<li><strong>August 13, 2025<\/strong>: Released LSQUIC v4.3.1 to the GitHub repository<\/li>\n<\/ul>\n<h2>Conclusion<\/h2>\n<p>We thank Imperva Offensive Team for bringing this issue to our attention. This vulnerability has been patched, so if you are keeping your LSQUIC library or your LiteSpeed server products up-to-date, there is nothing you need to do. If you have not updated in a while, please do so today.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have a security update for LiteSpeed\u2019s QUIC and HTTP\/3 Library (LSQUIC), and all three LiteSpeed server products. Recently we were made aware of a vulnerability affecting LSQUIC. We patched this vulnerability in v4.3.1. Please update to the latest versions of LSQUIC and all LiteSpeed server products. This Allocation of Resources Without Limits or Throttling [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":13161,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[26,27,29,23],"tags":[171],"class_list":["post-13159","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-load-balancer","category-web-server","category-openlitespeed","category-security","tag-lsquic"],"jetpack_featured_media_url":"https:\/\/lswp.store\/wp-content\/uploads\/2025\/08\/lsquic-vuln2-1.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/comments?post=13159"}],"version-history":[{"count":0,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/13159\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media\/13161"}],"wp:attachment":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media?parent=13159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/categories?post=13159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/tags?post=13159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}