VendorsCaddyservercaddyall versions
Vulnerabilities

Caddyserver Caddy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2018-21246
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
Published 2020-06-15 · Modified
9.8EPSS 0.027
CVE-2026-27590
Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport
Published 2026-02-24 · Analyzed
9.8EPSS 0.009
CVE-2026-27587
Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass
Published 2026-02-24 · Analyzed
9.1EPSS 0.005
CVE-2026-27588
Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass
Published 2026-02-24 · Analyzed
9.1EPSS 0.005
CVE-2026-27586
Caddy's mTLS client authentication silently fails open when CA certificate file is missing or malformed
Published 2026-02-24 · Analyzed
9.1EPSS 0.004
CVE-2026-30851
Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation
Published 2026-03-07 · Analyzed
8.8EPSS 0.003
CVE-2026-45135
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
Published 2026-06-23 · Analyzed
8.1EPSS 0.007
CVE-2026-52845
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
Published 2026-06-23 · Modified
8.1EPSS 0.004
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2022-34037
An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged when an administrator's bad configuration containing a malformed request URI caused the server to return an empty reply instead of a valid HTTP response to the client.
Published 2022-07-22 · Modified
7.5EPSS 0.012
CVE-2026-52844
Caddy: Windows `file_server` path authorization bypass via encoded backslash
Published 2026-06-23 · Analyzed
7.5EPSS 0.006
CVE-2026-30852
Caddy: vars_regexp double-expands user input, leaking env vars and files
Published 2026-03-07 · Analyzed
7.5EPSS 0.005
CVE-2026-27585
Caddy's improper sanitization of glob characters in file matcher may lead to bypassing security protections
Published 2026-02-24 · Analyzed
6.9EPSS 0.004
CVE-2026-27589
Caddy vulnerable to cross-origin config application via local admin API /load (caddy)
Published 2026-02-24 · Analyzed
6.9EPSS 0.002
CVE-2023-50463
The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).
Published 2023-12-10 · Modified
6.5EPSS 0.007
CVE-2022-28923
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
Published 2023-02-06 · Modified
6.1EPSS 0.014
CVE-2022-29718
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
Published 2022-06-02 · Modified
6.1EPSS 0.010
CVE-2026-45692
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
Published 2026-06-23 · Modified
5.4EPSS 0.002
CVE-2018-19148
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate for a randomly selected vhost in its configuration. Repeated requests (with a nonexistent hostname in the Host header) permit full enumeration of all certificates on the server. This generally permits an attacker to easily and accurately discover the existence of and relationships among hostnames that weren't meant to be public, though this information could likely have been discovered via other methods with additional effort.
Published 2018-11-10 · Modified
4.3EPSS 0.009
CVE-2026-52846
Caddy: stripHTML template function bypass
Published 2026-06-23 · Analyzed
4.2EPSS 0.002