Логотип exploitDog
bind:CVE-2026-27586
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-27586

Количество 4

Количество 4

ubuntu логотип

CVE-2026-27586

около 1 месяца назад

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate file is missing, unreadable, or malformed. The server starts without error but accepts any client certificate signed by any system-trusted CA, completely bypassing the intended private CA trust boundary. Any deployment using `trusted_ca_cert_file` or `trusted_ca_certs_pem_files` for mTLS will silently degrade to accepting any system-trusted client certificate if the CA file becomes unavailable. This can happen due to a typo in the path, file rotation, corruption, or permission changes. The server gives no indication that mTLS is misconfigured. Version 2.11.1 fixes the vulnerability.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-27586

около 1 месяца назад

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate file is missing, unreadable, or malformed. The server starts without error but accepts any client certificate signed by any system-trusted CA, completely bypassing the intended private CA trust boundary. Any deployment using `trusted_ca_cert_file` or `trusted_ca_certs_pem_files` for mTLS will silently degrade to accepting any system-trusted client certificate if the CA file becomes unavailable. This can happen due to a typo in the path, file rotation, corruption, or permission changes. The server gives no indication that mTLS is misconfigured. Version 2.11.1 fixes the vulnerability.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-27586

около 1 месяца назад

Caddy is an extensible server platform that uses TLS by default. Prior ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-hffm-g8v7-wrv7

около 1 месяца назад

Caddy: mTLS client authentication silently fails open when CA certificate file is missing or malformed

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-27586

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate file is missing, unreadable, or malformed. The server starts without error but accepts any client certificate signed by any system-trusted CA, completely bypassing the intended private CA trust boundary. Any deployment using `trusted_ca_cert_file` or `trusted_ca_certs_pem_files` for mTLS will silently degrade to accepting any system-trusted client certificate if the CA file becomes unavailable. This can happen due to a typo in the path, file rotation, corruption, or permission changes. The server gives no indication that mTLS is misconfigured. Version 2.11.1 fixes the vulnerability.

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-27586

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate file is missing, unreadable, or malformed. The server starts without error but accepts any client certificate signed by any system-trusted CA, completely bypassing the intended private CA trust boundary. Any deployment using `trusted_ca_cert_file` or `trusted_ca_certs_pem_files` for mTLS will silently degrade to accepting any system-trusted client certificate if the CA file becomes unavailable. This can happen due to a typo in the path, file rotation, corruption, or permission changes. The server gives no indication that mTLS is misconfigured. Version 2.11.1 fixes the vulnerability.

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-27586

Caddy is an extensible server platform that uses TLS by default. Prior ...

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-hffm-g8v7-wrv7

Caddy: mTLS client authentication silently fails open when CA certificate file is missing or malformed

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу