CVE-2025-24947: Litespeedtech Lsquic

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.0 allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This is caused by XXH32 usage.

Affected products

Published 2025-02-20. Last modified 2026-06-17.