Vulnerabilities > Caddyserver > Caddy > 2.4.6

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. 7.5
2023-02-06 CVE-2022-28923 Open Redirect vulnerability in Caddyserver Caddy 2.4.6
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
network
low complexity
caddyserver CWE-601
6.1
2022-06-02 CVE-2022-29718 Open Redirect vulnerability in Caddyserver Caddy
Caddy v2.4 was discovered to contain an open redirect vulnerability.
network
low complexity
caddyserver CWE-601
6.1