सुरक्षा सलाह पर वापस जाएँ

LiteSpeed CVE-2026-93903

CVE-2026-93903 is a vulnerability in LiteSpeed Web Server builds before 6.3.7 build 1, where internal redirect URL validation is mishandled in a certain corner case. NVD rates it Critical with a CVSS 3.1 base score of 9.4. Anyone running an affected LiteSpeed Web Server build should update to 6.3.7 build 1 or later.

Critical 9.4 CVSS
LiteSpeed

SharedLicense लाइसेंस के तहत इसका अर्थ

Because redirect URL validation fails in an edge case, an attacker may be able to reach internal targets through crafted requests; the full exploitability window is described only as a corner case by NVD.

LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain “corner case.”

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-93903

अक्सर पूछे जाने वाले प्रश्न

What is CVE-2026-93903?
It is the CVE ID for a flaw in LiteSpeed Web Server before 6.3.7 build 1 that mishandles internal redirect URL validation in a certain corner case. NVD assigns it CWE-174 (Interpretation Conflict) and a CVSS base score of 9.4.
Which LiteSpeed versions are affected?
LiteSpeed Web Server builds before 6.3.7 build 1 are affected. Builds at 6.3.7 build 1 or later contain the fix — this matches the DirectAdmin forum's separate advice that Enterprise 6.3.7 or later is required.
How do I fix CVE-2026-93903?
Update LiteSpeed Web Server Enterprise to 6.3.7 build 1 or later through your normal LiteSpeed update channel (or the WHM LiteSpeed plugin if installed), then confirm the running build in the LiteSpeed Web Admin console.
Is CVE-2026-93903 being exploited in the wild?
No confirmed exploitation has been announced, and NVD has not recorded exploit intelligence for this CVE yet. Given the critical rating, patch on a priority basis rather than waiting.

अपने सिस्टम में भेद्यताओं की जाँच करें

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

अपना सिस्टम जाँचें