Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

(Another) 16 Sep 2026 - LiteSpeed Enterprise security advisory (URGENT)

suriqsuriq Member

As I posted a few days ago [https://lowendtalk.com/discussion/221122/14-sep-2026-litespeed-enterprise-security-advisory-urgent], LiteSpeed just released another security update.

This is an additional fix for internal redirect URL validation. Original issue could allow a malicious website user to bypass account isolation, including CageFS.

If you already patched yesterday, update again to latest LiteSpeed Enterprise (6.3.7 build 1).

Email attached:

URGENT — Security Advisory
Following yesterday’s security advisory, LiteSpeed has released an additional update addressing another corner case in internal redirect URL validation.

Because the original vulnerability could allow a malicious website user to bypass expected account-isolation controls, including CageFS, we strongly recommend that all customers update again to the latest available LiteSpeed Web Server Enterprise release.

Affected: LiteSpeed Web Server Enterprise installations not running the latest available release
Status: Additional security fix available
Action required: Update immediately
ACTION REQUIRED (immediately)
Please upgrade LiteSpeed Web Server Enterprise to the latest available version.

This update (v6.3.7 build 1) includes the following additional security fix:

[Security] Address another corner case in internal redirect URL validation.
Even if you updated following yesterday’s advisory, please apply this latest update to ensure your server includes the additional validation improvement.

After upgrading, please review your server for unusual CGI activity or piped logging behavior and verify that server-level logging continues to function normally.

If you need assistance with the upgrade or have concerns about possible exposure, our support team is ready to help.

Thank you for your immediate attention to this security update.

LiteSpeed Team

Comments

  • instruction unclear. cog stuck in chicen farm and can't be pulled

    also is this vuln only affect the enterprise version? where's the official announcement/release link?

    Thanked by 1rpqu
  • forestforest Member

    lol

  • suriqsuriq Member

    @ScreenReader said:
    instruction unclear. cog stuck in chicen farm and can't be pulled

    also is this vuln only affect the enterprise version? where's the official announcement/release link?

    They only sent an email, no official link.

  • rpqurpqu Member

    LMAO

Sign In or Register to comment.