High severity7.5NVD Advisory· Published Aug 14, 2023· Updated Jun 17, 2026
CVE-2023-40518
CVE-2023-40518
Description
LiteSpeed OpenLiteSpeed before 1.7.18 does not strictly validate HTTP request headers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:*range: <1.7.18
- (no CPE)
- Range: <1.7.18
Patches
Vulnerability mechanics
References
2- openlitespeed.org/release-log/version-1-7-x/nvdRelease Notes
- www.litespeedtech.com/products/litespeed-web-server/release-lognvdRelease Notes
News mentions
0No linked articles in our index yet.