HTTP/2 Bomb Vulnerability
June 5th, 2026

LiteSpeed server products are effectively not vulnerable to HTTP/2 Bomb attacks. Learn why here.

Security Update for LSCWP
May 27th, 2026

We have a security update for LiteSpeed Cache for WordPress. A few months ago, we were made aware of a vulnerability in the LiteSpeed Cache for …

Security Update for LSCWP
October 29th, 2025

We have a security update for LiteSpeed Cache for WordPress. Recently we were made aware of a vulnerability in the LiteSpeed Cache for WordPress plugin. We …

LiteSpeed Security Update
August 18th, 2025

We have a security update for LiteSpeed’s QUIC and HTTP/3 Library (LSQUIC), and all three LiteSpeed server products. Recently we were made aware of a vulnerability …

LiteSpeed Not Affected By MadeYouReset
August 13th, 2025

Here is what you need to know about LiteSpeed and the HTTP/2 MadeYouReset vulnerability, specifically CVE-2025-8671: MadeYouReset uses malformed HTTP/2 control frames in order to break …

LSCWP Responsive Placeholders Patch
May 7th, 2025

Details about the recent LiteSpeed Cache v7.1 patch, which fixes CVE-2025-47437, a potential Server Side Request Forgery vulnerability.

LSQUIC Security Update
February 18th, 2025

This LSQUIC security update, patched in v4.2.0, addresses the Hash-based Denial-of-Service vulnerability, announced in CVE-2025-24947.