MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2025-54939

CVSS 5.3v3.1pub. 2025-08-01upd. 2025-08-27

LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • Litespeedtech Litespeed Web Adc

    APP
    Litespeedtech
    < 3.3.1
  • Litespeedtech Litespeed Web Server

    APP
    Litespeedtech
    < 6.3.4
  • Litespeedtech Lsquic

    APP
    Litespeedtech
    < 4.3.1
  • Litespeedtech Openlitespeed

    APP
    Litespeedtech
    < 1.8.4
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-25678CRITICAL9.8PL ✓same product

Błędna walidacja DCID w bibliotece LiteSpeed QUIC (LSQUIC)

CVE-2022-30592CRITICAL9.8PL ✓same product

NULL pointer dereference w LiteSpeed QUIC (LSQUIC) — obsługa MAX_TABLE_CAPACITY

CVE-2020-5519CRITICAL9.8PL ✓same product

Niewystarczająca walidacja żądań w WebAdmin Console OpenLiteSpeed

CVE-2026-31386HIGH8.6same product

OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerabi...

CVE-2023-40518HIGH7.5same product

LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.