Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.
References
Configurations
History
25 Feb 2026, 17:13
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Caddyserver
Caddyserver caddy |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CPE | cpe:2.3:a:caddyserver:caddy:*:*:*:*:*:*:*:* | |
| References | () https://github.com/caddyserver/caddy/blob/68d50020eef0d4c3398b878f17c8092ca5b58ca0/modules/caddyhttp/fileserver/matcher.go#L361 - Product | |
| References | () https://github.com/caddyserver/caddy/blob/68d50020eef0d4c3398b878f17c8092ca5b58ca0/modules/caddyhttp/fileserver/matcher.go#L398 - Product | |
| References | () https://github.com/caddyserver/caddy/releases/tag/v2.11.1 - Release Notes | |
| References | () https://github.com/caddyserver/caddy/security/advisories/GHSA-4xrr-hq4w-6vf4 - Exploit, Vendor Advisory |
24 Feb 2026, 17:29
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-24 17:29
Updated : 2026-02-25 17:13
NVD link : CVE-2026-27585
Mitre link : CVE-2026-27585
CVE.ORG link : CVE-2026-27585
JSON object : View
Products Affected
caddyserver
- caddy
CWE
CWE-20
Improper Input Validation
