{"id":"CVE-2026-92700","title":"Caddy is an extensible server platform that uses TLS by default","summary":"Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() uses case-sensitive filepath.Match checks, so case variants can bypass hide rule…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-178"],"vendor":"caddyserver","product":"caddy","affected":["caddy <= 2.11.3"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T20:17:22.137","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92700","references":[{"url":"https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9","label":"security-advisories@github.com"},{"url":"https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-23T19:22:40.555126Z"},"cvssSource":"cna","ingestedAt":"2026-09-23T18:29:33.263Z","slug":"CVE-2026-92700","body":"## Overview\n\nCaddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() uses case-sensitive filepath.Match checks, so case variants can bypass hide rules on case-insensitive filesystems or when mixed-case paths coexist and expose files intended to be hidden.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":209847,"id":"CVE-2026-92700","ts":1790191914338,"field":"exploit_available","old":"false","new":"true"}]}