Microsoft Security Response Center guidance
Release Notes
Vulnerability intelligence
CVE-2026-93682 and is rated Medium severity with a CVSS score of 5.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.