Back to Security Advisories
Critical 2026-08-06

Security Advisory: LiteSpeed Web Server Heap Overflow

LiteSpeed AlmaLinux 9 CentOS 7

A heap buffer overflow was identified in LiteSpeed Web Server HTTP/2 handling. A crafted request could cause a crash or remote code execution.

Affected Versions

6.0.4 and earlier

Patched Version

6.0.5

Default Update CMD

yum update -y

Fix Commands

CentOS 7

yum clean all
/usr/local/lsws/bin/lshttpd -v

AlmaLinux 9

dnf clean metadata
/usr/local/lsws/bin/lshttpd -v

A heap buffer overflow was identified in LiteSpeed Web Server HTTP/2 handling. A crafted request could cause a crash or remote code execution.

More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System