Internal Redirect URL Validation Flaw in LiteSpeed Web Server by LiteSpeed Technologies
CVE-2026-93903

9.4CRITICAL

Key Information:

Vendor
CVE Published:
30 September 2026

What is CVE-2026-93903?

The LiteSpeed Web Server prior to version 6.3.7 build 1 has a vulnerability that mishandles internal redirect URL validation, which can be exploited in specific scenarios. This flaw could potentially allow attackers to craft malicious requests that exploit the improper handling of internal redirects, leading to unintended behavior or security issues.

Affected Version(s)

LiteSpeed Web Server 0 < 6.3.7 build 1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.