Vulnerabilities > Caddyserver > Caddy > 2.4.1

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44487 Resource Exhaustion vulnerability in multiple products
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5
2022-06-02 CVE-2022-29718 Open Redirect vulnerability in Caddyserver Caddy
Caddy v2.4 was discovered to contain an open redirect vulnerability.
network
low complexity
caddyserver CWE-601
6.1