Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27585

Опубликовано: 24 фев. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:caddyserver:caddy:*:*:*:*:*:*:*:*
Версия до 2.11.1 (исключая)

EPSS

Процентиль: 29%
0.00105
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.

CVSS3: 6.5
debian
около 1 месяца назад

Caddy is an extensible server platform that uses TLS by default. Prior ...

github
около 1 месяца назад

Caddy: Improper sanitization of glob characters in file matcher may lead to bypassing security protections

EPSS

Процентиль: 29%
0.00105
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20