Caddyserver's vulnerability profile centers on Caddy, a single widely deployed web server and reverse proxy, whose positioning in the request path and TLS termination role makes its flaws consequential across diverse deployment contexts. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, have a moderate tendency toward confirmed in-the-wild exploitation, and frequently acquire public exploit code; the recurring weakness classes—including sensitive-information disclosure, improper authentication, case-sensitivity handling errors, input-validation gaps, and open-redirect flaws—reflect the authentication, TLS, and HTTP-parsing logic inherent to a modern web-server implementation. Defenders should prioritize Caddy updates and inventory deployments serving internet-facing services; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Caddyserver over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2026-52845HIGH Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identity header before copying the tru | Jun 23, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-52844HIGH Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server l | Jun 23, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-45135HIGH Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go mi | Jun 23, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-27590CRITICAL Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the | Feb 24, 2026 | 9.8 | 32 | NO | NO |
CVE-2018-21246CRITICAL Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode. | Jun 15, 2020 | 9.8 | 31 | NO | NO |
CVE-2026-27588CRITICAL Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured | Feb 24, 2026 | 9.1 | 30 | NO | NO |
CVE-2022-28923MEDIUM Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs. | Feb 6, 2023 | 6.1 | 30 | NO | YES |
CVE-2026-30851HIGH Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, all | Mar 7, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-27587CRITICAL Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match | Feb 24, 2026 | 9.1 | 29 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Caddyserver.
Media articles that mention a CVE ID that affects a product developed by Caddyserver — matched by CVE ID, not by vendor name.