caddyserver records
20 published records for vendor caddyserver.
Researcher profile
- Entered KEV
- 1 · 5%
- Weaponized
- 1 · 5%
- Pre-auth RCE
- 2
- With a fix record
- 95%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-287 Improper Authentication3
- CWE-20 Improper Input Validation3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-178 Improper Handling of Case Sensitivity2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-290 Authentication Bypass by Spoofing1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
40Plan | CVE-2018-21246No exploit | Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMcaddyserver · caddy · CWE-287 | Critical9.8 | — | 2.7% | Jun 15, 2020 |
35Monitor | CVE-2026-27590No exploit | Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transportcaddyserver · caddy · CWE-20 | High8.9 | — | 0.9% | Feb 24, 2026 |
35Monitor | CVE-2026-27586No exploit | Caddy's mTLS client authentication silently fails open when CA certificate file is missing or malformedcaddyserver · caddy · CWE-755 | High8.8 | — | 0.4% | Feb 24, 2026 |
35Monitor | CVE-2026-30851No exploit | Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalationcaddyserver · caddy · CWE-287 | High8.8 | — | 0.3% | Mar 7, 2026 |
32Monitor | CVE-2026-45135No exploit | Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Filescaddyserver · caddy · CWE-20 | High8.1 | — | 0.7% | Jun 23, 2026 |
32Monitor | CVE-2026-52845No exploit | Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`caddyserver · caddy · CWE-287 | High8.1 | — | 0.4% | Jun 23, 2026 |
30Monitor | CVE-2022-34037No exploit | An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial ofcaddyserver · caddy · CWE-125 | High7.5 | — | 1.2% | Jul 22, 2022 |
30Monitor | CVE-2026-52844No exploit | Caddy: Windows `file_server` path authorization bypass via encoded backslashcaddyserver · caddy · CWE-22 | High7.5 | — | 0.6% | Jun 23, 2026 |
30Monitor | CVE-2026-27587No exploit | Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypasscaddyserver · caddy · CWE-178 | High7.7 | — | 0.5% | Feb 24, 2026 |
30Monitor | CVE-2026-27588No exploit | Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypasscaddyserver · caddy · CWE-178 | High7.7 | — | 0.5% | Feb 24, 2026 |
27Monitor | CVE-2026-27585No exploit | Caddy's improper sanitization of glob characters in file matcher may lead to bypassing security protectionscaddyserver · caddy · CWE-20 | Medium6.9 | — | 0.4% | Feb 24, 2026 |
27Monitor | CVE-2026-27589No exploit | Caddy vulnerable to cross-origin config application via local admin API /load (caddy)caddyserver · caddy · CWE-352 | Medium6.9 | — | 0.2% | Feb 24, 2026 |
26Monitor | CVE-2023-50463No exploit | The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof theicaddyserver · caddy · CWE-290 | Medium6.5 | — | 0.7% | Dec 10, 2023 |
24Monitor | CVE-2022-28923Proof of concept | Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via ccaddyserver · caddy · CWE-601 | Medium6.1 | — | 1.4% | Feb 6, 2023 |
24Monitor | CVE-2022-29718No exploit | Caddy v2.4 was discovered to contain an open redirect vulnerability.caddyserver · caddy · CWE-601 | Medium6.1 | — | 1.0% | Jun 2, 2022 |
22Monitor | CVE-2026-30852No exploit | Caddy: vars_regexp double-expands user input, leaking env vars and filescaddyserver · caddy · CWE-74 | Medium5.5 | — | 0.5% | Mar 7, 2026 |
16Monitor | CVE-2026-52846No exploit | Caddy: stripHTML template function bypasscaddyserver · caddy · CWE-116 | Medium4.2 | — | 0.2% | Jun 23, 2026 |
15Monitor | CVE-2026-45692No exploit | Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalizationcaddyserver · caddy · CWE-187 | Low3.8 | — | 0.2% | Jun 23, 2026 |
14Monitor | CVE-2018-19148No exploit | Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames.caddyserver · caddy · CWE-200 | Low3.7 | — | 0.9% | Nov 10, 2018 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2018-2124640Plan
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostM
CriticalCVSS 9.8No exploitEPSS 3%caddyserver · caddyJun 15, 2020
- CVE-2026-2759035Monitor
Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport
HighCVSS 8.9No exploitEPSS 1%caddyserver · caddyFeb 24, 2026
- CVE-2026-2758635Monitor
Caddy's mTLS client authentication silently fails open when CA certificate file is missing or malformed
HighCVSS 8.8No exploitEPSS 0%caddyserver · caddyFeb 24, 2026
- CVE-2026-3085135Monitor
Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation
HighCVSS 8.8No exploitEPSS 0%caddyserver · caddyMar 7, 2026
- CVE-2026-4513532Monitor
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
HighCVSS 8.1No exploitEPSS 1%caddyserver · caddyJun 23, 2026
- CVE-2026-5284532Monitor
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
HighCVSS 8.1No exploitEPSS 0%caddyserver · caddyJun 23, 2026
- CVE-2022-3403730Monitor
An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of
HighCVSS 7.5No exploitEPSS 1%caddyserver · caddyJul 22, 2022
- CVE-2026-5284430Monitor
Caddy: Windows `file_server` path authorization bypass via encoded backslash
HighCVSS 7.5No exploitEPSS 1%caddyserver · caddyJun 23, 2026
- CVE-2026-2758730Monitor
Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass
HighCVSS 7.7No exploitEPSS 1%caddyserver · caddyFeb 24, 2026
- CVE-2026-2758830Monitor
Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass
HighCVSS 7.7No exploitEPSS 1%caddyserver · caddyFeb 24, 2026
- CVE-2026-2758527Monitor
Caddy's improper sanitization of glob characters in file matcher may lead to bypassing security protections
MediumCVSS 6.9No exploitEPSS 0%caddyserver · caddyFeb 24, 2026
- CVE-2026-2758927Monitor
Caddy vulnerable to cross-origin config application via local admin API /load (caddy)
MediumCVSS 6.9No exploitEPSS 0%caddyserver · caddyFeb 24, 2026
- CVE-2023-5046326Monitor
The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof thei
MediumCVSS 6.5No exploitEPSS 1%caddyserver · caddyDec 10, 2023
- CVE-2022-2892324Monitor
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via c
MediumCVSS 6.1Proof of conceptEPSS 1%caddyserver · caddyFeb 6, 2023
- CVE-2022-2971824Monitor
Caddy v2.4 was discovered to contain an open redirect vulnerability.
MediumCVSS 6.1No exploitEPSS 1%caddyserver · caddyJun 2, 2022
- CVE-2026-3085222Monitor
Caddy: vars_regexp double-expands user input, leaking env vars and files
MediumCVSS 5.5No exploitEPSS 0%caddyserver · caddyMar 7, 2026
- CVE-2026-5284616Monitor
Caddy: stripHTML template function bypass
MediumCVSS 4.2No exploitEPSS 0%caddyserver · caddyJun 23, 2026
- CVE-2026-4569215Monitor
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
LowCVSS 3.8No exploitEPSS 0%caddyserver · caddyJun 23, 2026
- CVE-2018-1914814Monitor
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames.
LowCVSS 3.7No exploitEPSS 1%caddyserver · caddyNov 10, 2018