CVE-2026-93903
Received
Received - Intake
LiteSpeed Web Server URL Validation Bypass
Vulnerability report for CVE-2026-93903, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-30
Last updated on: 2026-09-30
Assigner: MITRE
Description
Description
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| litespeed_technologies | litespeed_web_server | to 6.3.7 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-174 | The product decodes the same input twice, which can limit the effectiveness of any protection mechanism that occurs in between the decoding operations. |