Dependency scanning
Check whether github.com/caddyserver/caddy/v2 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-77281
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
CVE-2022-28923
Open Redirect in Caddy
CVE-2022-29718
Open redirect in caddy
GO-2026-5730
Caddy CVE-2026-30852 Fix Bypass
GO-2026-5408
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
CVE-2026-52846
Caddy: stripHTML template function bypass
CVE-2026-52845
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
CVE-2026-45135
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
CVE-2026-52844
Caddy: Windows `file_server` path authorization bypass via encoded backslash
GHSA-wwhq-w58m-w29c
Caddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy
CVE-2026-52846
Caddy: stripHTML template function bypass in github.com/caddyserver/caddy
CVE-2026-52844
Caddy: Windows file server path authorization bypass via encoded backslash in github.com/caddyserver/caddy
CVE-2026-45135
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files in github.com/caddyserver/caddy
CVE-2026-52845
Caddy: FastCGI header normalization bypass in forward_auth copy_headers in github.com/caddyserver/caddy
GHSA-gx7w-56w6-g48x
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy
CVE-2026-45692
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
CVE-2026-45692
Remote Admin Authorization Bypass in "/config" API via Array Index Normalization in github.com/caddyserver/caddy
CVE-2026-30852
Caddy's vars_regexp double-expands user input, leaking env vars and files in github.com/caddyserver/caddy
CVE-2026-30851
Caddy forward_auth copy_headers allows Identity Injection and Privilege Escalation in github.com/caddyserver/caddy
CVE-2026-27590
Caddy: Unicode case-folding length expansion causes incorrect split_path index in FastCGI transport
CVE-2026-27589
Caddy is vulnerable to cross-origin config application via local admin API /load
CVE-2026-27588
Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass
CVE-2026-27587
Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass
CVE-2026-27586
Caddy: mTLS client authentication silently fails open when CA certificate file is missing or malformed
CVE-2026-27585
Caddy: Improper sanitization of glob characters in file matcher may lead to bypassing security protections
CVE-2026-27588
Caddy MatchHost becomes case-sensitive in github.com/caddyserver/caddy/v2
CVE-2026-27590
Unicode case-folding causes incorrect split_path index in github.com/caddyserver/caddy/v2
CVE-2026-27586
Caddy mTLS authentication fails open in github.com/caddyserver/caddy/v2
CVE-2026-27585
Improper sanitization of glob characters in github.com/caddyserver/caddy/v2
CVE-2026-27587
Caddy MatchPath %xx branch skips case normalization in github.com/caddyserver/caddy/v2
CVE-2026-27589
Caddy is vulnerable to cross-origin config application via local admin API /load in github.com/caddyserver/caddy/v2
CVE-2022-28923
Open redirect in github.com/caddyserver/caddy/v2
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes