go

github.com/caddyserver/caddy/v2

View on go registry
32 Total advisories
32 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/caddyserver/caddy/v2 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.5
Go

CVE-2026-77281

Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass

MEDIUM 6.1
Go

CVE-2022-28923

Open Redirect in Caddy

MEDIUM 6.1
Go

CVE-2022-29718

Open redirect in caddy

UNKNOWN
Go

GO-2026-5730

Caddy CVE-2026-30852 Fix Bypass

MEDIUM 4.3
Go

GO-2026-5408

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching

MEDIUM 4.2
Go

CVE-2026-52846

Caddy: stripHTML template function bypass

HIGH 8.1
Go

CVE-2026-52845

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

HIGH 8.1
Go

CVE-2026-45135

Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files

HIGH 7.5
Go

CVE-2026-52844

Caddy: Windows `file_server` path authorization bypass via encoded backslash

UNKNOWN
Go

GHSA-wwhq-w58m-w29c

Caddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy

UNKNOWN
Go

CVE-2026-52846

Caddy: stripHTML template function bypass in github.com/caddyserver/caddy

UNKNOWN
Go

CVE-2026-52844

Caddy: Windows file server path authorization bypass via encoded backslash in github.com/caddyserver/caddy

UNKNOWN
Go

CVE-2026-45135

Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files in github.com/caddyserver/caddy

UNKNOWN
Go

CVE-2026-52845

Caddy: FastCGI header normalization bypass in forward_auth copy_headers in github.com/caddyserver/caddy

UNKNOWN
Go

GHSA-gx7w-56w6-g48x

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy

MEDIUM 5.4
Go

CVE-2026-45692

Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

UNKNOWN
Go

CVE-2026-45692

Remote Admin Authorization Bypass in "/config" API via Array Index Normalization in github.com/caddyserver/caddy

UNKNOWN
Go

CVE-2026-30852

Caddy's vars_regexp double-expands user input, leaking env vars and files in github.com/caddyserver/caddy

UNKNOWN
Go

CVE-2026-30851

Caddy forward_auth copy_headers allows Identity Injection and Privilege Escalation in github.com/caddyserver/caddy

UNKNOWN
Go

CVE-2026-27590

Caddy: Unicode case-folding length expansion causes incorrect split_path index in FastCGI transport

UNKNOWN
Go

CVE-2026-27589

Caddy is vulnerable to cross-origin config application via local admin API /load

UNKNOWN
Go

CVE-2026-27588

Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass

UNKNOWN
Go

CVE-2026-27587

Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass

UNKNOWN
Go

CVE-2026-27586

Caddy: mTLS client authentication silently fails open when CA certificate file is missing or malformed

UNKNOWN
Go

CVE-2026-27585

Caddy: Improper sanitization of glob characters in file matcher may lead to bypassing security protections

UNKNOWN
Go

CVE-2026-27588

Caddy MatchHost becomes case-sensitive in github.com/caddyserver/caddy/v2

UNKNOWN
Go

CVE-2026-27590

Unicode case-folding causes incorrect split_path index in github.com/caddyserver/caddy/v2

UNKNOWN
Go

CVE-2026-27586

Caddy mTLS authentication fails open in github.com/caddyserver/caddy/v2

UNKNOWN
Go

CVE-2026-27585

Improper sanitization of glob characters in github.com/caddyserver/caddy/v2

UNKNOWN
Go

CVE-2026-27587

Caddy MatchPath %xx branch skips case normalization in github.com/caddyserver/caddy/v2

UNKNOWN
Go

CVE-2026-27589

Caddy is vulnerable to cross-origin config application via local admin API /load in github.com/caddyserver/caddy/v2

UNKNOWN
Go

CVE-2022-28923

Open redirect in github.com/caddyserver/caddy/v2

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes