CVE-2022-29718Medium· 6.1▾ SunlitOpen redirect in caddy
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
github.com/caddyserver/caddy < 2.5.0github.com/caddyserver/caddy/v2 < 2.5.0Upgrade to a patched release:
github.com/caddyserver/caddy 2.5.0github.com/caddyserver/caddy/v2 2.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77281Medium· 6.5Caddy is an extensible server platform that uses TLS by default
GHSA-wwhq-w58m-w29cMediumCaddy CVE-2026-30852 Fix Bypass
GHSA-gx7w-56w6-g48xMedium· 4.3Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
CVE-2026-45692Medium· 5.4Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
GO-2026-5730NoneCaddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy
GO-2026-5408NoneCaddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy