PT-2026-42048 · Unknown · Caddy Defender

CVE-2026-46415

·

Published

2026-05-19

·

Updated

2026-07-30

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Caddy Defender versions prior to 0.10.1
Description The software incorrectly used r.RemoteAddr to evaluate whether a request should be blocked. In environments where Caddy is positioned behind a trusted proxy, CDN, or load balancer, RemoteAddr represents the address of the immediate peer (the proxy) rather than the original client. While Caddy resolves the actual client address into the client ip request variable based on the trusted proxies policy, the software failed to utilize this variable. Consequently, clients from blocked IP ranges can bypass blocking mechanisms if the trusted proxy's IP address is not blocked.
Recommendations Update to version 0.10.1 or later. Enforce equivalent IP blocking at the trusted proxy, CDN, load balancer, firewall, or other edge layer before traffic reaches Caddy.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46415
GHSA-3H23-RRPC-3P87
GO-2026-5086
OPENSUSE-SU-2026:21483-1

Affected Products

Caddy Defender