Vulnerabilities > Caddyserver > Caddy > 0.6.0

DATE CVE VULNERABILITY TITLE RISK
2023-12-10 CVE-2023-50463 Authentication Bypass by Spoofing vulnerability in Caddyserver Caddy 0.5.0/0.5.1/0.6.0
The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).
network
low complexity
caddyserver CWE-290
6.5
2023-10-10 CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. 7.5
2020-06-15 CVE-2018-21246 Improper Authentication vulnerability in Caddyserver Caddy
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
network
low complexity
caddyserver CWE-287
critical
9.8
2018-11-10 CVE-2018-19148 Information Exposure vulnerability in Caddyserver Caddy
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames.
network
high complexity
caddyserver CWE-200
3.7