Description
Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite() can pass attacker-controlled replacement bytes through buildQueryString for a second placeholder expansion when a rewrite URI ends with a literal question mark, allowing injected environment or request-variable placeholders to disclose data and, when the file provider is registered, allowing injected file placeholders to disclose readable files. The issue is fixed in version 2.11.4.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Caddy’s rewrite engine, before version 2.11.4, incorrectly passed attacker‑controlled replacement bytes through a second placeholder expansion when a URI rewrite ended with a literal question mark. This flaw allowed an attacker to inject environment or request‑variable placeholders that revealed sensitive data, and when the file provider module is enabled it also allowed file‑placeholder injection to read arbitrary files on the server. The vulnerability therefore leads to confidential information exposure rather than code execution.

Affected Systems

The issue affects the Caddy Server (caddyserver/caddy) in all releases up to and including 2.11.3. Any installation that uses the rewrite module with rules ending in a trailing question mark is vulnerable.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as moderate, and the EPSS score of less than 1% indicates a very low exploitation probability. The flaw is not listed in the CISA KEV catalog. Attackers could exploit the weakness by sending specially crafted HTTP requests containing the vulnerable rewrite rule to the server, thus triggering the placeholder re‑expansion. Once the path is triggered, exposed environment or file data can be retrieved by the attacker. The fix is available in v2.11.4 and onwards.

Generated by OpenCVE AI on September 18, 2026 at 23:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Caddy to version 2.11.4 or newer to apply the official patch.
  • Verify that rewrite rules do not end with an unescaped literal question mark; adjust the configuration to remove the trailing question mark if it is unnecessary.
  • If an immediate upgrade is not possible, disable the usage of environment or file placeholders in rewrite rules and consider temporarily disabling the file provider module until a patched version is deployed.

Generated by OpenCVE AI on September 18, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j8px-rmrx-76h9 Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Caddyserver
Caddyserver caddy
Vendors & Products Caddyserver
Caddyserver caddy

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite() can pass attacker-controlled replacement bytes through buildQueryString for a second placeholder expansion when a rewrite URI ends with a literal question mark, allowing injected environment or request-variable placeholders to disclose data and, when the file provider is registered, allowing injected file placeholders to disclose readable files. The issue is fixed in version 2.11.4.
Title Caddy: rewrite placeholder re-expansion
Weaknesses CWE-178
CWE-770
CWE-94
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

Caddyserver Caddy
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T14:43:34.818Z

Reserved: 2026-08-20T19:14:21.331Z

Link: CVE-2026-77281

cve-icon Vulnrichment

Updated: 2026-09-18T14:39:57.835Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T21:17:37.890

Modified: 2026-09-24T21:16:28.120

Link: CVE-2026-77281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:45:15Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity

  • CWE-770

    Allocation of Resources Without Limits or Throttling

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')