Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-27585

Опубликовано: 24 фев. 2026
Источник: debian

Описание

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
caddyunfixedpackage

Примечания

  • https://github.com/caddyserver/caddy/security/advisories/GHSA-4xrr-hq4w-6vf4

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.

CVSS3: 6.5
nvd
около 1 месяца назад

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.

github
около 1 месяца назад

Caddy: Improper sanitization of glob characters in file matcher may lead to bypassing security protections