Caddyserver Caddy vulnerabilities
23 known vulnerabilities affecting caddyserver/caddy.
Total CVEs
23
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH7MEDIUM9LOW2
Vulnerabilities
Page 2 of 2
CVE-2026-52846P4MEDIUMCVSS 4.2fixed in 2.11.42026-06-23
CVE-2026-52846 [MEDIUM] CWE-116 CVE-2026-52846: Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as img src=x onerror=alert()>, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HT
nvd
CVE-2026-45692P4LOWCVSS 3.8≥ 2.4.0, < 2.11.3v>= 2.4.0, < 2.11.32026-06-23
CVE-2026-45692 [LOW] CWE-187 CVE-2026-45692: Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the author
Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves to a different config object during traversal. This happens because the aut
nvd
CVE-2018-19148P4LOWCVSS 3.7≤ 0.11.02018-11-10
CVE-2018-19148 [LOW] CWE-200 CVE-2018-19148: Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate for a randomly selected vhost in its configuration. Repeated requests (with a nonexistent hostname in t
nvd
← Previous2 / 2