Skip to content
Noroxi

caddyserver records

20 published records for vendor caddyserver.

Researcher profile

Entered KEV
1 · 5%
Weaponized
1 · 5%
Pre-auth RCE
2
With a fix record
95%
Median publish → KEV
0 days

All records

20 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostM

    CriticalCVSS 9.8No exploitEPSS 3%

    caddyserver · caddyJun 15, 2020

  • Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport

    HighCVSS 8.9No exploitEPSS 1%

    caddyserver · caddyFeb 24, 2026

  • Caddy's mTLS client authentication silently fails open when CA certificate file is missing or malformed

    HighCVSS 8.8No exploitEPSS 0%

    caddyserver · caddyFeb 24, 2026

  • Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation

    HighCVSS 8.8No exploitEPSS 0%

    caddyserver · caddyMar 7, 2026

  • Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files

    HighCVSS 8.1No exploitEPSS 1%

    caddyserver · caddyJun 23, 2026

  • Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

    HighCVSS 8.1No exploitEPSS 0%

    caddyserver · caddyJun 23, 2026

  • An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of

    HighCVSS 7.5No exploitEPSS 1%

    caddyserver · caddyJul 22, 2022

  • Caddy: Windows `file_server` path authorization bypass via encoded backslash

    HighCVSS 7.5No exploitEPSS 1%

    caddyserver · caddyJun 23, 2026

  • Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass

    HighCVSS 7.7No exploitEPSS 1%

    caddyserver · caddyFeb 24, 2026

  • Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass

    HighCVSS 7.7No exploitEPSS 1%

    caddyserver · caddyFeb 24, 2026

  • Caddy's improper sanitization of glob characters in file matcher may lead to bypassing security protections

    MediumCVSS 6.9No exploitEPSS 0%

    caddyserver · caddyFeb 24, 2026

  • Caddy vulnerable to cross-origin config application via local admin API /load (caddy)

    MediumCVSS 6.9No exploitEPSS 0%

    caddyserver · caddyFeb 24, 2026

  • The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof thei

    MediumCVSS 6.5No exploitEPSS 1%

    caddyserver · caddyDec 10, 2023

  • Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via c

    MediumCVSS 6.1Proof of conceptEPSS 1%

    caddyserver · caddyFeb 6, 2023

  • Caddy v2.4 was discovered to contain an open redirect vulnerability.

    MediumCVSS 6.1No exploitEPSS 1%

    caddyserver · caddyJun 2, 2022

  • Caddy: vars_regexp double-expands user input, leaking env vars and files

    MediumCVSS 5.5No exploitEPSS 0%

    caddyserver · caddyMar 7, 2026

  • Caddy: stripHTML template function bypass

    MediumCVSS 4.2No exploitEPSS 0%

    caddyserver · caddyJun 23, 2026

  • Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

    LowCVSS 3.8No exploitEPSS 0%

    caddyserver · caddyJun 23, 2026

  • Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames.

    LowCVSS 3.7No exploitEPSS 1%

    caddyserver · caddyNov 10, 2018