PT-2026-103276 · Litespeed Technologies · Litespeed Web Server
CVE-2026-93903
·
Published
2026-09-30
·
Updated
2026-10-01
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
LiteSpeed Web Server (LSWS) versions prior to 6.3.7 build 1
Description
LiteSpeed Web Server (LSWS) mishandles internal redirect URL validation in a specific corner case. This issue involves double decoding of the same data, which can lead to security bypasses or unauthorized access.
Recommendations
Update LiteSpeed Web Server (LSWS) to version 6.3.7 build 1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Litespeed Web Server