CVE-2026-77281: Caddyserver Caddy
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite() can pass attacker-controlled replacement bytes through buildQueryString for a second placeholder expansion when a rewrite URI ends with a literal question mark, allowing injected environment or request-variable placeholders to disclose data and, when the file provider is registered, allowing injected file placeholders to disclose readable files. The issue is fixed in version 2.11.4.
Affected products
- Caddyserver Caddy: before 2.11.4 (fixed in 2.11.4)
Published 2026-09-17. Last modified 2026-09-24.