github.com/caddyserver/caddy/v2
Go15 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/caddyserver/caddy/v2page 1 of 1
- CVE-2022-28923MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.5.0-beta.12023-02-06
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
- CVE-2022-29718MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.5.02022-06-02
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
- CVE-2026-27585MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.11.12026-02-24
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects …
- CVE-2026-27586CRITICALCVSS 9.1EG 9.1✓ Fixed in 2.11.12026-02-24
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate f…
- CVE-2026-27587CRITICALCVSS 9.1EG 9.1✓ Fixed in 2.11.12026-02-24
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains percent-escape sequences (`%xx`) it compa…
- CVE-2026-27588CRITICALCVSS 9.1EG 9.1✓ Fixed in 2.11.12026-02-24
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host list (>100 entries) it becomes case-sens…
- CVE-2026-27589MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.11.12026-02-24
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint that replaces the entire running configura…
- CVE-2026-27590CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.11.12026-02-24
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and then uses that byte index to slice the ori…
- CVE-2026-30851HIGHCVSS 8.8EG 8.8✓ Fixed in 2.11.22026-03-07
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This iss…
- CVE-2026-30852HIGHCVSS 7.5EG 7.5✓ Fixed in 2.11.22026-03-07
Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 double-expands user-controlled input through the Caddy replacer. When vars_regexp matches …
- CVE-2026-45135HIGHCVSS 8.1EG 8.1✓ Fixed in 2.11.32026-05-18
Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when …
- CVE-2026-45692LOWCVSS 3.8EG 3.8✓ Fixed in 2.11.32026-05-19
Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one confi…
- CVE-2026-52844HIGHCVSS 7.5EG 7.5✓ Fixed in 2.11.42026-06-16
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as private\secret.txt o…
- CVE-2026-52845HIGHCVSS 8.1EG 8.1✓ Fixed in 2.11.42026-06-16
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identity header before copying the trusted value from the auth gateway. But when the request late…
- CVE-2026-52846MEDIUMCVSS 4.2EG 4.2✓ Fixed in 2.11.42026-06-16
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>,…
Check whether github.com/caddyserver/caddy/v2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/caddyserver/caddy/v2 CVEs against the assets you own.
Start Free Scan →