CVE-2026-93903: Critical severity LiteSpeed Web Server vulnerability
Published Sep 30, 2026
·Updated
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
Affected Software
1 affected component
LiteSpeed Web Server<6.3.7 build 1
Event History
Sep 30, 2026
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
DescriptionWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which LiteSpeed Web Server versions need to be reviewed?
The issue affects LiteSpeed Web Server releases before version 6.3.7 build 1. Upgrade to 6.3.7 build 1 or a later release.
2
What is known about exploitation requirements or affected configurations?
The available information only identifies a corner case involving internal redirect URL validation. It does not specify attacker prerequisites, affected default settings, exposure conditions, or a workaround if upgrading is not immediately possible.