A critical security vulnerability has been identified and patched in LiteSpeed Web Server (LSWS), the high-performance proprietary web server platform widely deployed across shared hosting providers, enterprise cloud stacks, and high-traffic WordPress infrastructures. Cataloged under CVE-2026-93903 and tracked in GitHub Advisory GHSA-8x5w-4247-99g6 with a CVSS v4.0 base score of 9.4 (Critical), the flaw allows remote attackers to bypass rewrite security directives and access restricted internal request handlers due to flawed internal redirect URL normalization.

The Scale of LiteSpeed in Global Hosting Infrastructure

LiteSpeed Web Server is favored by enterprise hosting platforms such as cPanel, Plesk, and DirectAdmin for its native Apache .htaccess compatibility, event-driven I/O engine, and specialized caching modules (LSCache). Because LSWS often serves as the frontline reverse proxy and HTTP/3 gateway for thousands of isolated virtual hosts on a single physical server, its URL parsing and access control mechanisms are mission-critical.

Vulnerability Mechanics: Internal Redirect Normalization Failure (CWE-174)

The flaw emerges within LiteSpeed's internal request forwarding subsystem. When an HTTP request triggers an internal redirect (such as an internal rewrite rule, custom error document dispatch, or pass-through handler), the server re-evaluates the target URI against the virtual host's routing tables.

In versions prior to 6.3.7 build 1, the internal redirect handler mishandles specific corner-case URL structures—particularly those incorporating non-canonical path encodings, multiple consecutive slashes, or trailing dot segments:

# Vulnerable Virtual Host Routing Pattern
RewriteEngine On
# Security Rule: Deny access to internal configuration endpoints
RewriteRule ^/internal/.*$ - [F,L]

# Exploitation Vector: Crafting corner-case internal redirect sequence
# An attacker submits an encoded URI that passes initial inspection:
GET /app/handler/..%2f..%2finternal/system_status HTTP/1.1
Host: hosting.tenant.internal

When the initial rewrite pass concludes, LiteSpeed dispatches an internal subrequest. During this secondary cycle, the URL normalization logic double-decodes the path without re-applying the directory-level prohibition rules. As a consequence, the subrequest executes against protected administrative handlers or scripts located outside the document root, bypassing authentication boundaries.

Impact Analysis on Multi-Tenant Environments

Security Domain Vulnerable State (< 6.3.7 b1) Remediated State (6.3.7 b1+)
Virtual Host Isolation Subrequests can traverse cross-vhost boundaries Strict canonical path resolution within vhost root
.htaccess Rule Enforcement Internal redirects bypass preceding rewrite flags Recursive inspection re-evaluates all security constraints
Handler Execution Unauthorized access to internal server-status and scripts Denied with 403 Forbidden on anomalous redirect paths

Remediation & Defense Actions

  1. Upgrade LiteSpeed Web Server Immediately: Deploy version 6.3.7 build 1 or higher via the command line or administrative WebAdmin console:
    /usr/local/lsws/admin/misc/lsup.sh -v 6.3.7
    /usr/local/lsws/bin/lswsctrl restart
  2. Audit Custom Rewrite Directives: Review virtual host configuration templates for dependencies on loose internal redirect chaining.
  3. Enforce Web Application Firewall (WAF) Filtering: Ensure ModSecurity rulesets (such as OWASP CRS) actively inspect incoming request URIs for anomalous percent-encoded dot-slash sequences prior to server engine ingestion.