PT-2026-95113 · Caddy · Caddy

·

CVE-2026-77281

·

Published

2026-09-17

·

Updated

2026-09-18

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Caddy versions prior to 2.11.4
Description Three configuration-dependent weaknesses affect the handler and placeholder layer.
First, in the Rewrite.Rewrite() function within modules/caddyhttp/rewrite/rewrite.go, a double-expansion issue occurs when a rewrite URI ends with a literal question mark. Attacker-controlled bytes can be passed through buildQueryString, triggering a second placeholder expansion. This allows the disclosure of environment variables via {env.X}, request variables via {vars.X}, and readable files via {file./path} if the file provider is registered.
Second, a memory exhaustion issue exists when using the {http.request.body} placeholder. The system reads the entire request body into a byte slice without a LimitReader, allowing an attacker to send an arbitrarily large body to trigger an Out-of-Memory (OOM) condition and crash the process.
Third, the fileHidden() function in modules/caddyhttp/fileserver/staticfiles.go uses case-sensitive matching via filepath.Match. On case-insensitive filesystems (such as macOS APFS and Windows NTFS), attackers can bypass the hide directive by using uppercase variations of the hidden file or directory names (e.g., accessing .GIT instead of .git), leading to the disclosure of sensitive files like .env or .git directories.
Recommendations Update Caddy to version 2.11.4. As a temporary mitigation for the rewrite issue, avoid using rewrite URIs that end with a literal question mark. As a temporary mitigation for the memory exhaustion issue, avoid using the {http.request.body} placeholder in configurations, such as in log append or CEL matchers, until the update is applied.

Exploit

Fix

Code Injection

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77281
GHSA-J8PX-RMRX-76H9

Affected Products

Caddy