Search CVE reports


Toggle filters

11 – 17 of 17 results


CVE-2026-27590

Medium priority
Needs evaluation

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and then uses that byte index to...

1 affected package

caddy

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
caddy Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2026-27589

Medium priority
Needs evaluation

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint that replaces the entire running...

1 affected package

caddy

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
caddy Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2026-27588

Medium priority
Needs evaluation

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host list (>100 entries) it becomes...

1 affected package

caddy

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
caddy Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2026-27587

Medium priority
Needs evaluation

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains percent-escape sequences (`%xx`)...

1 affected package

caddy

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
caddy Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2026-27586

Medium priority
Needs evaluation

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA...

1 affected package

caddy

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
caddy Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2026-27585

Medium priority
Needs evaluation

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It...

1 affected package

caddy

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
caddy Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2022-28923

Medium priority
Not affected

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

1 affected package

caddy

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
caddy — — Not in release Not in release Not in release
Show less packages