Back to Security Advisories
High 2026-05-05

Security Advisory: LiteSpeed Web Server HTTP/2 Request Smuggling

LiteSpeed AlmaLinux 8 AlmaLinux 9 CentOS 7 CloudLinux 8 CloudLinux 9

Improper header validation on the HTTP/2 stream permits request smuggling against proxied backends, enabling cache poisoning on shared hosting configurations.

Affected Versions

LiteSpeed Web Server 6.2.5 and earlier

Patched Version

LiteSpeed Web Server 6.2.6

Default Update CMD

yum update -y

Fix Commands

AlmaLinux 9 / CloudLinux 9

dnf update lsws
/usr/local/lsws/bin/lshttpd -r

AlmaLinux 8 / CloudLinux 8

dnf update lsws
/usr/local/lsws/bin/lshttpd -r

CentOS 7 / CloudLinux 7

yum update lsws
/usr/local/lsws/bin/lshttpd -r
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System