PT-2026-42048 · Unknown · Caddy Defender
CVE-2026-46415
·
Published
2026-05-19
·
Updated
2026-07-30
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Caddy Defender versions prior to 0.10.1
Description
The software incorrectly used
r.RemoteAddr to evaluate whether a request should be blocked. In environments where Caddy is positioned behind a trusted proxy, CDN, or load balancer, RemoteAddr represents the address of the immediate peer (the proxy) rather than the original client. While Caddy resolves the actual client address into the client ip request variable based on the trusted proxies policy, the software failed to utilize this variable. Consequently, clients from blocked IP ranges can bypass blocking mechanisms if the trusted proxy's IP address is not blocked.Recommendations
Update to version 0.10.1 or later.
Enforce equivalent IP blocking at the trusted proxy, CDN, load balancer, firewall, or other edge layer before traffic reaches Caddy.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Caddy Defender