caddyserver caddy是caddyserver团队开源的一款Web服务器软件。 caddyserver caddy 2.11.4之前版本存在输出处理不当漏洞,该漏洞源于stripHTML模板函数无法可靠移除所有HTML标签,某些畸形HTML可绕过标签剥离逻辑,可能导致客户端跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| caddyserver | caddy | < 2.11.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| caddyserver | caddy | < 2.11.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45135 | 8.1 HIGH | Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files |
| CVE-2026-52845 | 8.1 HIGH | Caddy: FastCGI header normalization bypass in `forward_auth copy_headers` |
| CVE-2026-52844 | 7.5 HIGH | Caddy: Windows `file_server` path authorization bypass via encoded backslash |
| CVE-2026-45692 | 5.4 MEDIUM | Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization |
No comments yet