VYPR

Caddy

by Caddy Project

Source repositories

CVEs (22)

  • CVE-2026-52846MedJun 23, 2026
    risk 0.20cvss 4.2epss 0.00

    Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>, can bypass the tag-stripping logic,…

  • CVE-2018-19148LowNov 10, 2018
    risk 0.17cvss 3.7epss 0.01

    Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate for a randomly selected…

Page 2 of 2