Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

caddy — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in caddy, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumeration (CWE) vulnerabilities associated with the Caddy web server software. It serves as a centralized resource for security researchers, system administrators, and developers to analyze the specific weakness types that have impacted this popular HTTP/2 web server over time. The page collects records of known security flaws, configuration errors, and implementation bugs that have been publicly disclosed or reported within the Caddy ecosystem. The data spans a continuous timeline, capturing vulnerabilities from the initial public releases of Caddy through to the most recent updates. This temporal scope ensures that users can observe trends in security posture and identify whether certain types of weaknesses are recurring issues or isolated incidents. By aggregating these records, the page offers a holistic view of the product's historical security landscape without requiring users to manually search through individual bulletin boards or changelogs. Visitors to this page can track advisories issued by the Caddy project and its community contributors to stay informed about critical patches. Furthermore, users can explore the specifics of particular vulnerability classes to understand how they manifest in the Caddy architecture. The interface allows for deep dives into individual vulnerability histories, enabling a thorough assessment of risk and aiding in the prioritization of security audits and mitigation efforts for infrastructure relying on this web server.

Vendor: caddyserver

CVE IDTitleCVSSSeverityPublished
CVE-2026-45135 Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files CWE-20 8.1 High2026-06-23
CVE-2026-45692 Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization CWE-187 5.4 Medium2026-06-23
CVE-2026-52845 Caddy: FastCGI header normalization bypass in `forward_auth copy_headers` CWE-287 8.1 High2026-06-23
CVE-2026-52844 Caddy: Windows `file_server` path authorization bypass via encoded backslash CWE-22 7.5 High2026-06-23
CVE-2026-52846 Caddy: stripHTML template function bypass CWE-116 4.2 Medium2026-06-23
CVE-2026-30851 Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation CWE-287 8.1 High2026-03-07
CVE-2026-30852 Caddy: vars_regexp double-expands user input, leaking env vars and files CWE-200 9.1 -2026-03-07
CVE-2026-27590 Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport CWE-20 9.8 -2026-02-24
CVE-2026-27589 Caddy vulnerable to cross-origin config application via local admin API /load (caddy) CWE-352 6.5 -2026-02-24
CVE-2026-27588 Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass CWE-178 9.1 -2026-02-24
CVE-2026-27587 Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass CWE-178 9.1 -2026-02-24
CVE-2026-27586 Caddy's mTLS client authentication silently fails open when CA certificate file is missing or malformed CWE-755 8.2 -2026-02-24
CVE-2026-27585 Caddy's improper sanitization of glob characters in file matcher may lead to bypassing security protections CWE-20 9.1 -2026-02-24

All 13 known CVE vulnerabilities affecting caddy with full Chinese analysis, references, and POCs where available.