Vulnerabilities > Caddyserver

DATE CVE VULNERABILITY TITLE RISK
2023-12-10 CVE-2023-50463 Authentication Bypass by Spoofing vulnerability in Caddyserver Caddy 0.5.0/0.5.1/0.6.0
The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).
network
low complexity
caddyserver CWE-290
6.5
2023-10-10 CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. 7.5
2023-02-06 CVE-2022-28923 Open Redirect vulnerability in Caddyserver Caddy 2.4.6
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
network
low complexity
caddyserver CWE-601
6.1
2022-07-22 CVE-2022-34037 Out-of-bounds Read vulnerability in Caddyserver Caddy 2.5.1
An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI.
network
low complexity
caddyserver CWE-125
7.5
2022-06-02 CVE-2022-29718 Open Redirect vulnerability in Caddyserver Caddy
Caddy v2.4 was discovered to contain an open redirect vulnerability.
network
low complexity
caddyserver CWE-601
6.1
2020-06-15 CVE-2018-21246 Improper Authentication vulnerability in Caddyserver Caddy
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
7.5
2018-11-10 CVE-2018-19148 Information Exposure vulnerability in Caddyserver Caddy
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames.
4.3