Caddyserver

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 20
    Known Exploited: 0
    5
    Critical Level Threats
    7
    High Level Threats
    7
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-45135

    Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files

    Last Modified: Jun 23, 2026
    Published: Jun 23, 2026

    CVE-2026-45692

    Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

    Last Modified: Jun 26, 2026
    Published: Jun 23, 2026

    CVE-2026-52845

    Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

    Last Modified: Jun 24, 2026
    Published: Jun 23, 2026

    CVE-2026-52844

    Caddy: Windows `file_server` path authorization bypass via encoded backslash

    Last Modified: Jun 23, 2026
    Published: Jun 23, 2026

    CVE-2026-52846

    Caddy: stripHTML template function bypass

    Last Modified: Jun 25, 2026
    Published: Jun 23, 2026
    Items Per Page