Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Caddy HIGH 8.1
CVE-2026-52845

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identit…

Fix: 2.11.4+
Fix from $1,950 2026-06-23
Caddy HIGH 7.5
CVE-2026-52844

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outsid…

Fix: 2.11.4+
Fix from $1,950 2026-06-23
Caddy HIGH 8.1
CVE-2026-45135

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/rev…

Fix: 2.11.3+
Fix from $1,950 2026-06-23
Caddy HIGH 8.8
CVE-2026-30851

Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not str…

Fix: 2.11.2+
Fix from $1,950 2026-03-07
Caddy HIGH 7.5
CVE-2026-30852

Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 …

Fix: 2.11.2+
Fix from $1,950 2026-03-07
Caddy CRITICAL 9.8
CVE-2026-27590

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split ind…

Fix: 2.11.1+
Fix from $2,300 2026-02-24
Caddy CRITICAL 9.1
CVE-2026-27588

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-i…

Fix: 2.11.1+
Fix from $2,300 2026-02-24
Caddy MEDIUM 6.5
CVE-2026-27589

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`)…

Fix: 2.11.1+
Fix from $1,600 2026-02-24
Caddy CRITICAL 9.1
CVE-2026-27586

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` …

Fix: 2.11.1+
Fix from $2,300 2026-02-24
Caddy CRITICAL 9.1
CVE-2026-27587

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-…

Fix: 2.11.1+
Fix from $2,300 2026-02-24
Caddy MEDIUM 6.5
CVE-2026-27585

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanit…

Fix: 2.11.1+
Fix from $1,600 2026-02-24
Caddy MEDIUM 6.5
CVE-2023-50463

The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source …

Fix: after 0.6.0
Fix from $1,600 2023-12-10
Caddy HIGH 7.5
CVE-2023-44487 KEVEPSS 100%

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploite…

Fix: 0.17.0 / 1.20.10+
Fix from $1,950 2023-10-10
Caddy MEDIUM 6.1
CVE-2022-28923

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted UR…

Patch available
Fix from $1,600 2023-02-06
Caddy HIGH 7.5
CVE-2022-34037

An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service …

Patch available
Fix from $1,950 2022-07-22
Caddy MEDIUM 6.1
CVE-2022-29718

Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect use…

Fix: 2.5.0+
Fix from $1,600 2022-06-02
Caddy CRITICAL 9.8
CVE-2018-21246

Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching m…

Fix: 0.10.3+
Fix from $2,300 2020-06-15