Lsquic
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-24947 | Med | 0.27 | 5.3 | 0.01 | Feb 20, 2025 | A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.0 allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs… | ||
| CVE-2025-54939 | Med | 0.00 | 5.3 | 0.01 | Aug 1, 2025 | LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak. | ||
| CVE-2024-25678 | Cri | 0.00 | 9.8 | 0.00 | Feb 9, 2024 | In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled. | ||
| CVE-2022-30592 | Cri | 0.00 | 9.8 | 0.03 | May 11, 2022 | liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY. |
- risk 0.27cvss 5.3epss 0.01
A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.0 allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs…
- risk 0.00cvss 5.3epss 0.01
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
- risk 0.00cvss 9.8epss 0.00
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
- risk 0.00cvss 9.8epss 0.03
liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.