CVE-2025-54939: Litespeedtech LiteSpeed Web ADC

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

Affected products

Published 2025-08-01. Last modified 2026-06-17.