Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

14 Sep 2026 - LiteSpeed Enterprise security advisory (URGENT)

suriqsuriq Member

Hello,

Got urgent security alert from litespeed about a critical vuln that can potentially allow account user to escape CageFS and get root:

Email attached:

URGENT — Security Advisory
A critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server.

This could allow an attacker to access or alter other hosted websites and the server itself.

This issue can bypass expected account isolation controls, including CageFS, allowing a malicious website user to potentially escape its restricted environment and gain root-level access to the server.

Affected: LiteSpeed Web Server Enterprise installations prior to v6.3.7
Status: Fix available
Severity: Critical

ACTION REQUIRED (immediately)
We strongly recommend upgrading all affected LiteSpeed Enterprise installations to:

LiteSpeed Web Server Enterprise 6.3.7 or later

The v6.3.7 update includes the following:

[Security] Enhance lscgid request authentication and validation.
[Security] Apply stronger validation of internal redirect URL.
[Security] Block setting of important internal-use environment variables from .htaccess.
[Feature] Enable post-quantum cryptography key exchange.
[Improvement] Add support for the MKCALENDAR request method.
[Bug fix] Address a race condition corner case for ModSecurity engine.
[Bug fix] Address an internal URL cache corner case.
[Bug fix] Improve Node.js process management to avoid lingering idle workers.
[Bug fix] Address HTTP/3 idle connection timeout issue.
[Bug fix] Address a namespace issue for natively configured vhost.
[Bug fix] Address a corner case in SHM locking.

Important Post-Upgrade Note
The stable v6.3.7 release includes an adjustment that permits tightly controlled, root-owned binaries to continue operating safely.

After upgrading, please review your server for unusual CGI activity or piped logging behavior and verify that server-level logging continues to function normally.

Please take action as soon as possible to secure your servers. If you need assistance with the upgrade or have concerns about possible exposure, our support team is ready to help.

Thank you for your immediate attention to this critical security update.

LiteSpeed Team

Thanked by 3forest tzuli buggedout

Comments

  • NameBigNameBig Member, Patron Provider

    :|

  • forestforest Member

    I don't get why people use LightSpeed and not just Apache.

  • IncognionIncognion Member

    @forest said:
    I don't get why people use LightSpeed and not just Apache.

    Because
    1. most of them don't know how to optimise their server/website due to lack of technical knowledge.

    1. Litghtspeed somehow able to successfully associate their name with speed (website's). So most of people think their websites work faster with lightspeed only. And if they don't use it, then they will left behind..
    Thanked by 1forest
  • nikionikio Member

    @forest said:
    I don't get why people use LightSpeed and not just Apache.

    s/Apache/nginx.

    FTFY

    On another note, maybe all of the braindead shared hosting vulnerabilities will finally convince some of my consulting clients to switch to proper website stacks instead of idling on this hole-filled crap.

    Thanked by 1tentor
  • NameBigNameBig Member, Patron Provider
    edited 7:56AM

    @forest said:
    I don't get why people use LightSpeed and not just Apache.

    Litespeed gives hosting providers an advantage not because it's faster or better than Apache, but because it's a marketing word. Most people who want web hosting ask for it, and if they do, web hosts will supply it because of demand rather than because it's faster or better than Apache. However, I agree with Litespeed's excellent performance in terms of WordPress acceleration.
    ~Vikas

  • forestforest Member

    @nikio said: s/Apache/nginx.

    FTFY

    I agree, but LightSpeed is designed to be a "replacement" for Apache specifically. That's the only reason I mentioned it.

  • suutsuut Member
    edited 8:19AM

    Are DirectAdmin and cPanel affected? :|

  • suriqsuriq Member

    @suut said:
    Are DirectAdmin and cPanel affected? :|

    yes, potentially, a cpanel or directadmin server running litespeed could be affected.

  • LeviLevi Veteran

    Litespeed is:

    • proprietary code. Well supported for corporate needs.
    • A good code. They are fast with their lscache plugin.
    • Convenient. It just works. Reaps benefits from both: nginx and apache (modules, syntax)
Sign In or Register to comment.