CVE-2026-93903
CRITICAL
9,4
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain 'corner case.'
174
Double Decoding of the Same Data
DraftCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Availability
Integrity
Other
Potential Impacts:
Bypass Protection Mechanism
Execute Unauthorized Code Or Commands
Varies By Context
Applicable Platforms
All platforms may be affected
https://docs.litespeedtech.com/lsws/changelog/#v6-3-7-build-1
https://www.litespeedtech.com/products/litespeed-web-server/release-log