CVE-2026-30851

Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This issue has been patched in version 2.11.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:caddyserver:caddy:*:*:*:*:*:*:*:*

History

11 Mar 2026, 13:06

Type Values Removed Values Added
CPE cpe:2.3:a:caddyserver:caddy:*:*:*:*:*:*:*:*
First Time Caddyserver
Caddyserver caddy
Summary
  • (es) Caddy es una plataforma de servidor extensible que utiliza TLS por defecto. Desde la versión 2.10.0 hasta antes de la versión 2.11.2, forward_auth copy_headers no elimina los encabezados proporcionados por el cliente, permitiendo la inyección de identidad y la escalada de privilegios. Este problema ha sido parcheado en la versión 2.11.2.
References () https://github.com/caddyserver/caddy/issues/6610 - () https://github.com/caddyserver/caddy/issues/6610 - Issue Tracking
References () https://github.com/caddyserver/caddy/pull/6608 - () https://github.com/caddyserver/caddy/pull/6608 - Issue Tracking, Patch
References () https://github.com/caddyserver/caddy/pull/7545 - () https://github.com/caddyserver/caddy/pull/7545 - Issue Tracking, Patch
References () https://github.com/caddyserver/caddy/security/advisories/GHSA-7r4p-vjf4-gxv4 - () https://github.com/caddyserver/caddy/security/advisories/GHSA-7r4p-vjf4-gxv4 - Exploit, Mitigation, Patch, Vendor Advisory

07 Mar 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-07 17:15

Updated : 2026-03-11 13:06


NVD link : CVE-2026-30851

Mitre link : CVE-2026-30851

CVE.ORG link : CVE-2026-30851


JSON object : View

Products Affected

caddyserver

  • caddy
CWE
CWE-287

Improper Authentication

CWE-345

Insufficient Verification of Data Authenticity