LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NLitespeedtech Openlitespeed
APPLitespeedtech< 1.7.18
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2020-5519CRITICAL9.8PL ✓same product
Niewystarczająca walidacja żądań w WebAdmin Console OpenLiteSpeed
CVE-2026-31386HIGH8.6same product
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerabi...
CVE-2022-0073HIGH8.8same product
Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web S...
CVE-2022-0074HIGH8.8same product
Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Serve...
CVE-2021-26758HIGH8.8same product
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain...