Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.
References
Configurations
History
No history.
Information
Published : 2026-02-24 17:29
Updated : 2026-02-25 17:13
NVD link : CVE-2026-27585
Mitre link : CVE-2026-27585
CVE.ORG link : CVE-2026-27585
JSON object : View
Products Affected
caddyserver
- caddy
CWE
CWE-20
Improper Input Validation
