Vulnerabilities in caddyserver

13 results
Vexday analysis

O Caddy Server apresenta 13 vulnerabilidades registradas, com 5 delas publicadas nos últimos 90 dias, indicando atividade recente de descobertas. Não há evidência de exploração ativa em campo (0 KEV) e nenhuma vulnerabilidade crítica catalogada, o que reduz a urgência imediata. A fraqueza dominante CWE-178 (Improper Handling of Case Sensitivity) sugere problemas de validação que requerem atenção em ciclos regulares de patch.

CVE-2026-27590HIGHCaddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transportEPSS 0.5%CVE-2026-45135HIGHCaddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP FilesEPSS 0.5%CVE-2026-52844HIGHCaddy: Windows `file_server` path authorization bypass via encoded backslashEPSS 0.5%CVE-2026-30852MEDIUMCaddy: vars_regexp double-expands user input, leaking env vars and filesEPSS 0.4%CVE-2026-27587HIGHCaddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypassEPSS 0.4%CVE-2026-27588HIGHCaddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypassEPSS 0.4%CVE-2026-27585MEDIUMCaddy's improper sanitization of glob characters in file matcher may lead to bypassing security protectionsEPSS 0.3%CVE-2026-52845HIGHCaddy: FastCGI header normalization bypass in `forward_auth copy_headers`EPSS 0.3%CVE-2026-27586HIGHCaddy's mTLS client authentication silently fails open when CA certificate file is missing or malformedEPSS 0.3%CVE-2026-30851HIGHCaddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege EscalationEPSS 0.2%CVE-2026-52846MEDIUMCaddy: stripHTML template function bypassEPSS 0.2%CVE-2026-45692MEDIUMCaddy: Remote Admin Authorization Bypass in `/config` API via Array Index NormalizationEPSS 0.2%CVE-2026-27589MEDIUMCaddy vulnerable to cross-origin config application via local admin API /load (caddy)EPSS 0.2%