pkg:Debian/caddy
7 total CVEsCRITICAL4MEDIUM3
✅ Check your installed version
All known vulnerabilities
- CRITICAL9.8CVE-2026-27590Caddy: Unicode case-folding length expansion causes incorrect split_path index in FastCGI transportfrom 0
- from 0
- CRITICAL9.1CVE-2026-27587Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypassfrom 0
- from 0
- MEDIUM6.5CVE-2026-27589Caddy is vulnerable to cross-origin config application via local admin API /loadfrom 0
- MEDIUM6.5CVE-2026-27585Caddy: Improper sanitization of glob characters in file matcher may lead to bypassing security protectionsfrom 0
- from 0, < 2.5.2-1