Caddyserver / Caddy
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-92700 | Caddy: fileHidden() case-sensitive pattern bypass — exposes "hidden" files via case variation | MEDIUM | 6.3 | Sep 23, 2026 |
| CVE-2026-92284 | Caddy: Unbounded body buffer via {http.request.body} placeholder — memory exhaustion DoS | MEDIUM | 6.9 | Sep 23, 2026 |
| CVE-2026-77281 | Caddy: rewrite placeholder re-expansion | MEDIUM | 6.5 | Sep 17, 2026 |
| CVE-2026-45135 | Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files | HIGH | 8.1 | Jun 23, 2026 |
| CVE-2026-45692 | Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization | MEDIUM | 5.4 | Jun 23, 2026 |
| CVE-2026-52845 | Caddy: FastCGI header normalization bypass in `forward_auth copy_headers` | HIGH | 8.1 | Jun 23, 2026 |
| CVE-2026-52844 | Caddy: Windows `file_server` path authorization bypass via encoded backslash | HIGH | 7.5 | Jun 23, 2026 |
| CVE-2026-52846 | Caddy: stripHTML template function bypass | MEDIUM | 4.2 | Jun 23, 2026 |
| CVE-2026-30851 | Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation | HIGH | 8.8 | Mar 7, 2026 |
| CVE-2026-30852 | Caddy: vars_regexp double-expands user input, leaking env vars and files | MEDIUM | 5.5 | Mar 7, 2026 |
| CVE-2026-27590 | Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport | HIGH | 8.9 | Feb 24, 2026 |
| CVE-2026-27589 | Caddy vulnerable to cross-origin config application via local admin API /load (caddy) | MEDIUM | 6.9 | Feb 24, 2026 |
| CVE-2026-27588 | Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass | HIGH | 7.7 | Feb 24, 2026 |
| CVE-2026-27587 | Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass | HIGH | 7.7 | Feb 24, 2026 |
| CVE-2026-27586 | Caddy's mTLS client authentication silently fails open when CA certificate file is missing or malformed | HIGH | 8.8 | Feb 24, 2026 |
| CVE-2026-27585 | Caddy's improper sanitization of glob characters in file matcher may lead to bypassing security protections | MEDIUM | 6.9 | Feb 24, 2026 |
| CVE-2023-50463 | The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address… | MEDIUM | 6.5 | Dec 10, 2023 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2022-28923 | caddy: an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs | HIGH | 7.5 | Feb 6, 2023 |
| CVE-2022-34037 | caddy: oob read allows for DoS | HIGH | 7.5 | Jul 22, 2022 |
| CVE-2022-29718 | Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbi… | MEDIUM | 6.1 | Jun 2, 2022 |
| CVE-2018-21246 | Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode. | CRITICAL | 9.8 | Jun 15, 2020 |
| CVE-2018-19148 | Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unabl… | LOW | 3.7 | Nov 10, 2018 |
Showing 1 to 23 of 23 CVEs