NA

CVE-2023-40518

Published: 14/08/2023 Updated: 22/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

LiteSpeed OpenLiteSpeed prior to 1.7.18 does not strictly validate HTTP request headers.

Vulnerable Product Search on Vulmon Subscribe to Product

litespeedtech openlitespeed

Github Repositories

Differential testing and fuzzing of HTTP servers and proxies

The HTTP Garden The HTTP Garden is a collection of HTTP servers and proxies configured to be composable, along with scripts to interact with them in a way that makes finding vulnerabilities much much easier For some cool demos of the vulnerabilities that you can find with the HTTP Garden, check out our ShmooCon 2024 talk Acknowledgements We'd like to thank our friends at