Impact
Caddy’s rewrite engine, before version 2.11.4, incorrectly passed attacker‑controlled replacement bytes through a second placeholder expansion when a URI rewrite ended with a literal question mark. This flaw allowed an attacker to inject environment or request‑variable placeholders that revealed sensitive data, and when the file provider module is enabled it also allowed file‑placeholder injection to read arbitrary files on the server. The vulnerability therefore leads to confidential information exposure rather than code execution.
Affected Systems
The issue affects the Caddy Server (caddyserver/caddy) in all releases up to and including 2.11.3. Any installation that uses the rewrite module with rules ending in a trailing question mark is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as moderate, and the EPSS score of less than 1% indicates a very low exploitation probability. The flaw is not listed in the CISA KEV catalog. Attackers could exploit the weakness by sending specially crafted HTTP requests containing the vulnerable rewrite rule to the server, thus triggering the placeholder re‑expansion. Once the path is triggered, exposed environment or file data can be retrieved by the attacker. The fix is available in v2.11.4 and onwards.
OpenCVE Enrichment
Github GHSA