CVE-2026-52846Medium· 4.2▾ SunlitCaddy: stripHTML template function bypass
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.2%
Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely.
The vulnerability originates from funcStripHTML in:
caddy/caddy/caddyhttp/templates/tplcontext.go
func (TemplateContext) funcStripHTML(s string) string {
var buf bytes.Buffer
var inTag, inQuotes bool
var tagStart int
for i, ch := range s {
if inTag {
if ch == '>' && !inQuotes {
inTag = false
} else if ch == '<' && !inQuotes {
// false start
buf.WriteString(s[tagStart:i])
tagStart = i
} else if ch == '"' {
inQuotes = !inQuotes
}
continue
}
if ch == '<' {
inTag = true
tagStart = i
continue
}
buf.WriteRune(ch)
}
if inTag {
// false start
buf.WriteString(s[tagStart:])
}
return buf.String()
}
Caddyfile setup
:8080 {
root * ./site
file_server
templates
}
Template file (index.html)
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>StripHTML Bypass Test</title>
</head>
<body>
<p>{{ stripHTML "<<>img src=x onerror=alert('XSS')>" }}</p>
</body>
</html>
The payload exploits the false start branch to smuggle a literal < back into the output, then uses the following > to terminate the parser’s tag state, leaving a valid <img ...> tag behind.
Tested in v2.11.3
Malformed HTML can bypass stripHTML, potentially allowing arbitrary HTML or JavaScript to be rendered if the output is used unsafely, leading to client-side XSS.
AI assisted in writing the report description; however, the discovery of the issue has been done manually.
github.com/caddyserver/caddy/v2 <= 2.11.3github.com/caddyserver/caddy <= 1.0.5Upgrade to a patched release:
github.com/caddyserver/caddy/v2 2.11.4Connected by shared product, vendor, weakness, or advisory.
GO-2026-5730NoneCaddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy
GO-2026-5408NoneCaddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching in github.com/caddyserver/caddy
GHSA-wwhq-w58m-w29cMediumCaddy CVE-2026-30852 Fix Bypass
GHSA-gx7w-56w6-g48xMedium· 4.3Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
CVE-2026-45135High· 8.1Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
CVE-2026-45692Medium· 5.4Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization