7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/caddyserver/caddy is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.1
CVE-2022-29718
Open redirect in caddy
HIGH 7.5
CVE-2022-34037
Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service
MEDIUM 4.2
CVE-2026-52846
Caddy: stripHTML template function bypass
HIGH 8.1
CVE-2026-52845
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
HIGH 7.5
CVE-2026-52844
Caddy: Windows `file_server` path authorization bypass via encoded backslash
LOW 3.7
CVE-2018-19148
Caddy allows enumeration of Certificates and Hostnames
CRITICAL 9.8
CVE-2018-21246
Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes