VYPR

Caddy

by Caddy Project

Source repositories

CVEs (25)

  • CVE-2022-28923MedFeb 6, 2023
    risk 0.33cvss 6.1epss 0.01

    Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

  • CVE-2022-29718MedJun 2, 2022
    risk 0.33cvss 6.1epss 0.01

    Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

  • CVE-2026-45692MedJun 23, 2026
    risk 0.28cvss 5.4epss 0.00

    Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves…

  • CVE-2026-52846MedJun 23, 2026
    risk 0.20cvss 4.2epss 0.00

    Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>, can bypass the tag-stripping logic,…

  • CVE-2018-19148LowNov 10, 2018
    risk 0.17cvss 3.7epss 0.01

    Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate for a randomly selected…

Page 2 of 2