CVE Watchtower

← Back to CVE List

CVE-2026-77281NVD

Description

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite() can pass attacker-controlled replacement bytes through buildQueryString for a second placeholder expansion when a rewrite URI ends with a literal question mark, allowing injected environment or request-variable placeholders to disclose data and, when the file provider is registered, allowing injected file placeholders to disclose readable files. The issue is fixed in version 2.11.4.
Severity Level
MEDIUM (6.5)
Published Date
17/09/2026
Last Modified
18/09/2026
Exploitation Status
????
EPSS Score
0.36% (percentile 29.8%)

CVSS Base Metrics

CVSS v3 (3.1)
MEDIUM 6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Weaknesses (CWE)

CWE-94 - CWE-94: Improper Control of Generation of Code ('Code Injection')CWE-178 - CWE-178: Improper Handling of Case SensitivityCWE-770 - CWE-770: Allocation of Resources Without Limits or Throttling

Affected & Patched Versions

ProductAffected VersionsPatched Version
caddyserver caddy< 2.11.4N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.