<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – caddy</title>
  <link>https://cvedaily.com/pages/tags/caddy.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/caddy.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – caddy</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-30852 – Caddy is an extensible server platform that uses TLS by default. From version 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30852</guid>
    <pubDate>Sat, 07 Mar 2026 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30852</strong></p>
  <p>Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 double-expands user-controlled input through the Caddy replacer. When vars_regexp matches against a placeholder like {http.request.header.X-Input}, the header value gets resolved once (expected), then passed through repl.ReplaceAll() again (the bug).…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30851 – Caddy is an extensible server platform that uses TLS by default. From version 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30851</guid>
    <pubDate>Sat, 07 Mar 2026 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30851</strong></p>
  <p>Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This issue has been patched in version 2.11.2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27590 – Caddy is an extensible server platform that uses TLS by default. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27590</guid>
    <pubDate>Tue, 24 Feb 2026 17:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27590</strong></p>
  <p>Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and then uses that byte index to slice the original path. This is unsafe for Unicode because `strings.ToLower()` can change UTF-8 byte length for some characters. As a result, Caddy can derive an incorrect…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27589 – Caddy is an extensible server platform that uses TLS by default. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27589</guid>
    <pubDate>Tue, 24 Feb 2026 17:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27589</strong></p>
  <p>Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint that replaces the entire running configuration. When origin enforcement is not enabled (`enforce_origin` not configured), the admin endpoint accepts cross-origin requests (e.g., from attacker-controlled…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27588 – Caddy is an extensible server platform that uses TLS by default. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27588</guid>
    <pubDate>Tue, 24 Feb 2026 17:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27588</strong></p>
  <p>Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host list (>100 entries) it becomes case-sensitive due to an optimized matching path. An attacker can bypass host-based routing and any access controls attached to that route by changing the casing of the…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27587 – Caddy is an extensible server platform that uses TLS by default. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27587</guid>
    <pubDate>Tue, 24 Feb 2026 17:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27587</strong></p>
  <p>Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains percent-escape sequences (`%xx`) it compares against the request's escaped path without lowercasing. An attacker can bypass path-based routing and any access controls attached to that route by changing…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27586 – Caddy is an extensible server platform that uses TLS by default. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27586</guid>
    <pubDate>Tue, 24 Feb 2026 17:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27586</strong></p>
  <p>Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate file is missing, unreadable, or malformed. The server starts without error but accepts any client certificate signed by any system-trusted CA, completely bypassi…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27585 – Caddy is an extensible server platform that uses TLS by default. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27585</guid>
    <pubDate>Tue, 24 Feb 2026 17:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27585</strong></p>
  <p>Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25748 – authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25748</guid>
    <pubDate>Thu, 12 Feb 2026 20:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25748</strong></p>
  <p>authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy. When a malicious cookie was used, none of the authentik-specific X-Authentik-* headers were set which depending on applica…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30207 – Kirby is an open-source content management system. A vulnerability in versions p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30207</guid>
    <pubDate>Tue, 13 May 2025 16:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30207</strong></p>
  <p>Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that use PHP's built-in server. Such setups are commonly only used during local development. Sites that use other server software (such as Apache, nginx or Caddy) are not affected. A missing path traversal check allowed attackers to navigate all files on th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21500 – All versions of the package github.com/greenpau/caddy-security are vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21500</guid>
    <pubDate>Sat, 17 Feb 2024 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21500</strong></p>
  <p>All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes, attackers can bypass this blocking mechanism by automating the application’s full multistep 2FA process.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21499 – All versions of the package github.com/greenpau/caddy-security are vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21499</guid>
    <pubDate>Sat, 17 Feb 2024 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21499</strong></p>
  <p>All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms or confusion in handling TLS.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-644</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21498 – All versions of the package github.com/greenpau/caddy-security are vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21498</guid>
    <pubDate>Sat, 17 Feb 2024 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21498</strong></p>
  <p>All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this vulnerability.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21497 – Versions of the package github.com/greenpau/caddy-security  are vulnerable to Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21497</guid>
    <pubDate>Sat, 17 Feb 2024 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21497</strong></p>
  <p>Versions of the package github.com/greenpau/caddy-security  are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit this vulnerability, the user must take an action, such as clicking on a portal button or using the browser’s back button…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21496 – All versions of the package github.com/greenpau/caddy-security are vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21496</guid>
    <pubDate>Sat, 17 Feb 2024 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21496</strong></p>
  <p>All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Referer header, due to improper input sanitization. Although the Referer header is sanitized by escaping some characters that can allow XSS (e.g., [&], [<], [>], ["], [']), it does not account for the attack based on the JavaScript URL scheme (e.g., javascript:alert(document.domain)…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21495 – Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21495</guid>
    <pubDate>Sat, 17 Feb 2024 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21495</strong></p>
  <p>Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could possibly be predicted via a brute-force search. Attackers could use the potentially predictable nonce value used for authentication purposes in the OAuth flow to conduct OAuth replay attacks. In addition, insecure rand…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21494 – All versions of the package github.com/greenpau/caddy-security are vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21494</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21494</guid>
    <pubDate>Sat, 17 Feb 2024 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21494</strong></p>
  <p>All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This could lead to unauthorized access if the system trusts this spoofed IP address.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21494">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21493 – All versions of the package github.com/greenpau/caddy-security are vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21493</guid>
    <pubDate>Sat, 17 Feb 2024 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21493</strong></p>
  <p>All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access elements, which can lead to a panic (index out of range). Panics during the parsing of a configuration file may introduce ambig…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21492 – All versions of the package github.com/greenpau/caddy-security are vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21492</guid>
    <pubDate>Sat, 17 Feb 2024 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21492</strong></p>
  <p>All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User sessions remain valid even after requests are sent to /logout and /oauth2/google/logout. Attackers who gain access to an active but supposedly logged-out session can perform unauthorized actions on beha…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52430 – The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET reques...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52430</guid>
    <pubDate>Mon, 12 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52430</strong></p>
  <p>The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ substring.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-49854 – Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Sma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49854</guid>
    <pubDate>Mon, 18 Dec 2023 11:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-49854</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Smart Side Cart for WooCommerce.This issue affects Caddy – Smart Side Cart for WooCommerce: from n/a through 1.9.7.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-50463 – The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_he...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50463</guid>
    <pubDate>Sun, 10 Dec 2023 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-50463</strong></p>
  <p>The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45084 – An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45084</guid>
    <pubDate>Tue, 05 Dec 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45084</strong></p>
  <p>An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts data availability and integrity.  This issue only impacts SoftIron HyperCloud "density" storage nodes running HyperCloud software versions 1.0 to b…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-820</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-28923 – Caddy v2.4.6 was discovered to contain an open redirection vulnerability which a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28923</guid>
    <pubDate>Mon, 06 Feb 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-28923</strong></p>
  <p>Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34037 – An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34037</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34037</guid>
    <pubDate>Fri, 22 Jul 2022 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34037</strong></p>
  <p>An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged when an administrator's bad configuration containing a malformed request URI caused the server to return an empty reply…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34037">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29718 – Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29718</guid>
    <pubDate>Thu, 02 Jun 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29718</strong></p>
  <p>Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-21246 – Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21246</guid>
    <pubDate>Mon, 15 Jun 2020 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-21246</strong></p>
  <p>Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14243 – headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the masterc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14243</guid>
    <pubDate>Tue, 23 Jul 2019 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14243</strong></p>
  <p>headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, allows remote attackers to cause a denial of service (webserver panic and daemon crash) via a crafted HAProxy PROXY v2 request with truncated source/destination address data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2018-19148 – Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19148</guid>
    <pubDate>Sat, 10 Nov 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2018-19148</strong></p>
  <p>Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate for a randomly selected vhost in its configuration. Repeated requests (with a nonexistent hostname in the Host header) permit full enumeration of al…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-5963 – An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5963</guid>
    <pubDate>Sun, 12 Feb 2017 04:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-5963</strong></p>
  <p>An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5963">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
