Internal Redirect URL Validation Flaw in LiteSpeed Web Server by LiteSpeed Technologies
CVE-2026-93903
9.4CRITICAL
What is CVE-2026-93903?
The LiteSpeed Web Server prior to version 6.3.7 build 1 has a vulnerability that mishandles internal redirect URL validation, which can be exploited in specific scenarios. This flaw could potentially allow attackers to craft malicious requests that exploit the improper handling of internal redirects, leading to unintended behavior or security issues.
Affected Version(s)
LiteSpeed Web Server 0 < 6.3.7 build 1
