Vulnerabilities > Caddyserver > Caddy > 2.5.1

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44487 Resource Exhaustion vulnerability in multiple products
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5
2022-07-22 CVE-2022-34037 Out-of-bounds Read vulnerability in Caddyserver Caddy 2.5.1
An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI.
network
low complexity
caddyserver CWE-125
7.5