| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j8px-rmrx-76h9 | Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 20 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Caddyserver
Caddyserver caddy |
|
| Vendors & Products |
Caddyserver
Caddyserver caddy |
Thu, 17 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite() can pass attacker-controlled replacement bytes through buildQueryString for a second placeholder expansion when a rewrite URI ends with a literal question mark, allowing injected environment or request-variable placeholders to disclose data and, when the file provider is registered, allowing injected file placeholders to disclose readable files. The issue is fixed in version 2.11.4. | |
| Title | Caddy: rewrite placeholder re-expansion | |
| Weaknesses | CWE-178 CWE-770 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-18T14:43:34.818Z
Reserved: 2026-08-20T19:14:21.331Z
Link: CVE-2026-77281
Updated: 2026-09-18T14:39:57.835Z
Status : Received
Published: 2026-09-17T21:17:37.890
Modified: 2026-09-18T15:17:12.747
Link: CVE-2026-77281
No data.
OpenCVE Enrichment
Updated: 2026-09-18T23:45:15Z
Github GHSA