Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77281— Caddy: rewrite placeholder re-expansion

Quick assessment

Affected
caddyserver caddy
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Caddy 是一个可扩展的服务器平台,默认使用 TLS。在 2.11.3 及更早版本中,三个与配置相关的弱点影响了处理程序和占位符层。在 中,当重写 URI 以字面问号结尾时, 会将攻击者控制的替换字节传递到 进行第二次占位符扩展,从而允许注入的环境变量或请求变量占位符泄露数据;当注册了文件提供程序时,注入的文件占位符还可泄露可读文件内容。该问题已在 2.11.4 版本中修复。

CVSS 6.5 · Medium EPSS 0.36% · P30
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77281

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Caddy: rewrite placeholder re-expansion
Source: CVE Program / CVE List V5
Vulnerability Description
Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite() can pass attacker-controlled replacement bytes through buildQueryString for a second placeholder expansion when a rewrite URI ends with a literal question mark, allowing injected environment or request-variable placeholders to disclose data and, when the file provider is registered, allowing injected file placeholders to disclose readable files. The issue is fixed in version 2.11.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
caddyserver caddy < 2.11.4 -

II. Public POCs for CVE-2026-77281

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77281

登录查看更多情报信息。

Patches & Fixes for CVE-2026-77281 (2)

Vendor Advisories for CVE-2026-77281 (1)

Vendor Pages for CVE-2026-77281 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77281

No comments yet


Leave a comment