Caddyserver
13 known vulnerabilities
Top Products
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function ca
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat
Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and th
Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitP
Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_r
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_a
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (def
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request ma
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request ma
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `Clien
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine
Frequently Asked Questions
How many CVEs affect Caddyserver?
Caddyserver has 13 CVE records in our database, including 4 critical and 5 high severity vulnerabilities.
What are the most severe Caddyserver vulnerabilities?
Caddyserver has 4 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Caddyserver vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Caddyserver products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Caddyserver Vulnerabilities
CyberStrike scans your infrastructure for Caddyserver vulnerabilities and provides real-time remediation guidance.
Get Started