Authcrunch provides authentication and security middleware for the Caddy web server, a narrowly scoped product line that handles sensitive credential and session management. Recurring vulnerabilities cluster around input sanitization and session-control weaknesses—including cross-site scripting, brute-force resistance, session expiration, and server-side request forgery—typical of authentication-layer components where parser rigor and state boundaries matter directly to security isolation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Authcrunch over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-21492HIGH All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign O | Feb 17, 2024 | 8.1 | 22 | NO | NO |
CVE-2024-21496MEDIUM All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Referer header, due to improper input sanitization. Although the | Feb 17, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-52430MEDIUM The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ sub | Feb 12, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-21500MEDIUM All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). | Feb 17, 2024 | 6.5 | 17 | NO | NO |
CVE-2024-21498MEDIUM All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose | Feb 17, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Authcrunch.
Media articles that mention a CVE ID that affects a product developed by Authcrunch — matched by CVE ID, not by vendor name.