High severity7.5NVD Advisory· Published Jul 22, 2022· Updated Jun 17, 2026
CVE-2022-34037
CVE-2022-34037
Description
An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged when an administrator's bad configuration containing a malformed request URI caused the server to return an empty reply instead of a valid HTTP response to the client.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/caddyserver/caddyGo | < 2.5.2 | 2.5.2 |
Affected products
7- osv-coords5 versionspkg:rpm/opensuse/caddy&distro=openSUSE%20Tumbleweedpkg:golang/github.com/caddyserver/caddypkg:apk/chainguard/kubernetes-dns-node-cache-1.17pkg:rpm/opensuse/caddy&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/caddy&distro=SUSE%20Package%20Hub%2015%20SP4
< 2.5.2-2.1+ 4 more
- (no CPE)range: < 2.5.2-2.1
- (no CPE)range: < 2.5.2
- (no CPE)range: < 0
- (no CPE)range: < 2.5.2-bp154.2.8.1
- (no CPE)range: < 2.5.2-bp154.2.8.1
- Caddy/Caddydescription
- cpe:2.3:a:caddyserver:caddy:2.5.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- github.com/caddyserver/caddy/issues/4775nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-m7gr-5w5g-36jfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-34037ghsaADVISORY
- github.com/caddyserver/caddy/commit/693e9b5283e675b56084ecc83d73176cab0ee27cghsaWEB
- github.com/caddyserver/caddy/issues/4775nvdWEB
News mentions
0No linked articles in our index yet.