CVE-2026-93903

Summary

LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."

Affected Software

VendorProductVersion RangeStatus
litespeedtechLiteSpeed Web Server0 < 6.3.7 build 1affected

Weaknesses

  • CWE-174: CWE-174 Double Decoding of the Same Data

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References