CVE-2026-77281Medium· 6.5▾ SunlitCaddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite()…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite() can pass attacker-controlled replacement bytes through buildQueryString for a second placeholder expansion when a rewrite URI ends with a literal question mark, allowing injected environment or request-variable placeholders to disclose data and, when the file provider is registered, allowing injected file placeholders to disclose readable files. The issue is fixed in version 2.11.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/caddyserver/caddy/v2 <= 2.11.3Patched in:
github.com/caddyserver/caddy/v2 2.11.4Connected by shared product, vendor, weakness, or advisory.
CVE-2022-29718Medium· 6.1Open redirect in caddy
GHSA-wwhq-w58m-w29cMediumCaddy CVE-2026-30852 Fix Bypass
GHSA-gx7w-56w6-g48xMedium· 4.3Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
CVE-2026-45135High· 8.1Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
CVE-2026-45692Medium· 5.4Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
GO-2026-5730NoneCaddy CVE-2026-30852 Fix Bypass in github.com/caddyserver/caddy