Whiskerent

#44821of 57,427
6.5Total CVSS
Vulnerabilities · 1
PT-2026-95113
6.5
2026-09-17
Caddy · Caddy · CVE-2026-77281
**Name of the Vulnerable Software and Affected Versions** Caddy versions prior to 2.11.4 **Description** Three configuration-dependent weaknesses affect the handler and placeholder layer. First, in the `Rewrite.Rewrite()` function within `modules/caddyhttp/rewrite/rewrite.go`, a double-expansion issue occurs when a rewrite URI ends with a literal question mark. Attacker-controlled bytes can be passed through `buildQueryString`, triggering a second placeholder expansion. This allows the disclosure of environment variables via `{env.X}`, request variables via `{vars.X}`, and readable files via `{file./path}` if the file provider is registered. Second, a memory exhaustion issue exists when using the `{http.request.body}` placeholder. The system reads the entire request body into a byte slice without a `LimitReader`, allowing an attacker to send an arbitrarily large body to trigger an Out-of-Memory (OOM) condition and crash the process. Third, the `fileHidden()` function in `modules/caddyhttp/fileserver/staticfiles.go` uses case-sensitive matching via `filepath.Match`. On case-insensitive filesystems (such as macOS APFS and Windows NTFS), attackers can bypass the `hide` directive by using uppercase variations of the hidden file or directory names (e.g., accessing `.GIT` instead of `.git`), leading to the disclosure of sensitive files like `.env` or `.git` directories. **Recommendations** Update Caddy to version 2.11.4. As a temporary mitigation for the rewrite issue, avoid using rewrite URIs that end with a literal question mark. As a temporary mitigation for the memory exhaustion issue, avoid using the `{http.request.body}` placeholder in configurations, such as in `log append` or CEL matchers, until the update is applied.