Back to Security Advisories

Security Advisory: LiteSpeed Web Server HTTP/2 Request Smuggling

Improper header validation on the HTTP/2 stream permits request smuggling against proxied backends, enabling cache poisoning on shared hosting configurations.

High
LiteSpeed AlmaLinux 8 AlmaLinux 9 CentOS 7 CloudLinux 8 CloudLinux 9

Affected Versions

LiteSpeed Web Server 6.2.5 and earlier

Patched Version

LiteSpeed Web Server 6.2.6

Default Update CMD

yum update -y

Fix Commands

AlmaLinux 9 / CloudLinux 9

dnf update lsws
/usr/local/lsws/bin/lshttpd -r

AlmaLinux 8 / CloudLinux 8

dnf update lsws
/usr/local/lsws/bin/lshttpd -r

CentOS 7 / CloudLinux 7

yum update lsws
/usr/local/lsws/bin/lshttpd -r

Check your system for vulnerabilities

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Check Your System