PT-2026-95113 · Caddy · Caddy
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Caddy versions prior to 2.11.4
Description
Three configuration-dependent weaknesses affect the handler and placeholder layer.
First, in the
Rewrite.Rewrite() function within modules/caddyhttp/rewrite/rewrite.go, a double-expansion issue occurs when a rewrite URI ends with a literal question mark. Attacker-controlled bytes can be passed through buildQueryString, triggering a second placeholder expansion. This allows the disclosure of environment variables via {env.X}, request variables via {vars.X}, and readable files via {file./path} if the file provider is registered.Second, a memory exhaustion issue exists when using the
{http.request.body} placeholder. The system reads the entire request body into a byte slice without a LimitReader, allowing an attacker to send an arbitrarily large body to trigger an Out-of-Memory (OOM) condition and crash the process.Third, the
fileHidden() function in modules/caddyhttp/fileserver/staticfiles.go uses case-sensitive matching via filepath.Match. On case-insensitive filesystems (such as macOS APFS and Windows NTFS), attackers can bypass the hide directive by using uppercase variations of the hidden file or directory names (e.g., accessing .GIT instead of .git), leading to the disclosure of sensitive files like .env or .git directories.Recommendations
Update Caddy to version 2.11.4.
As a temporary mitigation for the rewrite issue, avoid using rewrite URIs that end with a literal question mark.
As a temporary mitigation for the memory exhaustion issue, avoid using the
{http.request.body} placeholder in configurations, such as in log append or CEL matchers, until the update is applied.Exploit
Fix
Code Injection
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Caddy