Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-27585

Опубликовано: 24 фев. 2026
Источник: debian
EPSS Низкий

Описание

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
caddyfixed2.11.2-1package

Примечания

  • https://github.com/caddyserver/caddy/security/advisories/GHSA-4xrr-hq4w-6vf4

EPSS

Процентиль: 25%
0.00323
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
6 месяцев назад

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.

CVSS3: 6.5
nvd
6 месяцев назад

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.

github
6 месяцев назад

Caddy: Improper sanitization of glob characters in file matcher may lead to bypassing security protections

EPSS

Процентиль: 25%
0.00323
Низкий