Caddy · Caddy · CVE-2026-77281
**Name of the Vulnerable Software and Affected Versions**
Caddy versions prior to 2.11.4
**Description**
Three configuration-dependent weaknesses affect the handler and placeholder layer.
First, in the `Rewrite.Rewrite()` function within `modules/caddyhttp/rewrite/rewrite.go`, a double-expansion issue occurs when a rewrite URI ends with a literal question mark. Attacker-controlled bytes can be passed through `buildQueryString`, triggering a second placeholder expansion. This allows the disclosure of environment variables via `{env.X}`, request variables via `{vars.X}`, and readable files via `{file./path}` if the file provider is registered.
Second, a memory exhaustion issue exists when using the `{http.request.body}` placeholder. The system reads the entire request body into a byte slice without a `LimitReader`, allowing an attacker to send an arbitrarily large body to trigger an Out-of-Memory (OOM) condition and crash the process.
Third, the `fileHidden()` function in `modules/caddyhttp/fileserver/staticfiles.go` uses case-sensitive matching via `filepath.Match`. On case-insensitive filesystems (such as macOS APFS and Windows NTFS), attackers can bypass the `hide` directive by using uppercase variations of the hidden file or directory names (e.g., accessing `.GIT` instead of `.git`), leading to the disclosure of sensitive files like `.env` or `.git` directories.
**Recommendations**
Update Caddy to version 2.11.4.
As a temporary mitigation for the rewrite issue, avoid using rewrite URIs that end with a literal question mark.
As a temporary mitigation for the memory exhaustion issue, avoid using the `{http.request.body}` placeholder in configurations, such as in `log append` or CEL matchers, until the update is applied.