Caddyserver

Caddy

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.37%
  • Veröffentlicht 24.02.2026 16:26:40
  • Zuletzt bearbeitet 25.02.2026 17:11:25

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains percent-escape sequences (`%xx`) it compares against...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 24.02.2026 16:08:20
  • Zuletzt bearbeitet 25.02.2026 17:14:19

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate file is miss...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 24.02.2026 16:06:05
  • Zuletzt bearbeitet 25.02.2026 17:13:16

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with ...

  • EPSS 0.66%
  • Veröffentlicht 10.12.2023 23:15:07
  • Zuletzt bearbeitet 21.11.2024 08:37:02

The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy dire...

Warnung Medienbericht Exploit
  • EPSS 100%
  • Veröffentlicht 10.10.2023 14:15:10
  • Zuletzt bearbeitet 12.05.2026 15:10:32

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Exploit
  • EPSS 1.43%
  • Veröffentlicht 06.02.2023 23:15:09
  • Zuletzt bearbeitet 26.03.2025 19:15:17

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

Exploit
  • EPSS 0.95%
  • Veröffentlicht 22.07.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:08:49

An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the ...

  • EPSS 0.98%
  • Veröffentlicht 02.06.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:59:36

Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

  • EPSS 2.72%
  • Veröffentlicht 15.06.2020 17:15:09
  • Zuletzt bearbeitet 21.11.2024 04:03:16

Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.

Exploit
  • EPSS 0.86%
  • Veröffentlicht 10.11.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:25

Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate...