Direct Vulnerabilities

Known vulnerabilities in the caddy package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-w9p8-pvxh-rxpj

<2.11.3-r3
  • L
GHSA-5cv4-jp36-h3mw

<2.11.3-r3
  • L
Cross-site Scripting (XSS)

<2.11.3-r3
  • L
GHSA-cg87-vwwh-xvgj

<2.11.3-r3
  • L
Improper Restriction of Rendered UI Layers or Frames

<2.11.3-r3
  • L
Resource Exhaustion

<2.11.3-r3
  • L
Improper Restriction of Rendered UI Layers or Frames

<2.11.3-r3
  • L
GHSA-m9x8-m34x-fj9q

<2.11.3-r3
  • L
Improper Restriction of Rendered UI Layers or Frames

<2.11.3-r3
  • L
GHSA-wrh2-89vg-4j9g

<2.11.3-r3
  • L
Missing Authorization

<2.11.3-r2
  • L
Improper Verification of Cryptographic Signature

<2.11.3-r2
  • L
Integer Overflow or Wraparound

<2.11.3-r2
  • L
Deserialization of Untrusted Data

<2.11.3-r2
  • L
Incorrect Type Conversion or Cast

<2.11.3-r2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.11.2-r15
  • C
SQL Injection

<2.11.2-r13
  • L
GHSA-j88v-2chj-qfwx

<2.11.2-r13
  • L
GHSA-w8rr-5gcm-pp58

<2.11.2-r12
  • L
Uncontrolled Memory Allocation

<2.11.2-r12
  • L
GHSA-7mr4-xjxg-34g6

<2.11.2-r11
  • H
Improper Certificate Validation

<2.11.2-r11
  • L
GHSA-gjvh-7jh8-7xhm

<2.11.2-r11
  • H
Incorrect Authorization

<2.11.2-r11
  • M
Allocation of Resources Without Limits or Throttling

<2.11.2-r11
  • H
Allocation of Resources Without Limits or Throttling

<2.11.2-r11
  • L
GHSA-x4jj-h2v8-hqqv

<2.11.2-r11
  • L
GHSA-jrg3-gfjw-hm96

<2.11.2-r11
  • L
GHSA-5w89-2c2x-6x66

<2.11.2-r11
  • L
CVE-2026-32280

<2.11.2-r11
  • M
Cross-site Scripting (XSS)

<2.11.2-r11
  • L
GHSA-m4pr-4j3g-9v7v

<2.11.2-r11
  • H
Untrusted Search Path

<2.11.2-r10
  • L
GHSA-hfvc-g4fc-pqhx

<2.11.2-r10
  • L
GHSA-78h2-9frx-2jm8

<2.11.2-r9
  • L
Uncaught Exception

<2.11.2-r9
  • L
Improper Authentication

<2.11.2-r7
  • L
GHSA-q4r8-xm5f-56gw

<2.11.2-r7
  • L
Improper Authorization

<2.11.2-r6
  • L
GHSA-p77j-4mvh-x3m3

<2.11.2-r6
  • L
CVE-2026-27141

<2.11.1-r2
  • L
GHSA-8fj7-8h3w-xwfm

<2.11.1-r2
  • H
Improper Verification of Cryptographic Signature

<2.11.0-r0
  • L
GHSA-69x3-g4r3-p962

<2.11.0-r0
  • L
Improper Initialization

<2.10.2-r10
  • L
GHSA-fw7p-63qq-7hpr

<2.10.2-r10
  • C
CVE-2025-68121

<2.10.2-r9
  • L
GHSA-h355-32pf-p2xm

<2.10.2-r9
  • L
GHSA-8jvr-vh7g-f8gx

<2.10.2-r9
  • L
CVE-2025-61732

<2.10.2-r9
  • L
GHSA-hcg3-q754-cr77

<2.9.1-r6
  • L
CVE-2024-28180

<2.8.4-r0
  • L
Improper Validation of Specified Type of Input

<2.10.0-r1
  • L
GHSA-c5q2-7r4c-mv6g

<2.8.4-r0
  • L
GHSA-g754-hx8w-x2g6

<2.10.2-r7
  • L
Allocation of Resources Without Limits or Throttling

<2.10.2-r7
  • L
GHSA-j7c9-79x7-8hpr

<2.10.2-r6
  • L
Incorrect Authorization

<2.10.2-r6
  • C
Improper Authentication

<2.10.2-r6
  • L
GHSA-h8cp-697h-8c8p

<2.10.2-r6
  • L
CVE-2025-47914

<2.10.2-r4
  • L
GHSA-f6x5-jh6r-wrfv

<2.10.2-r4
  • L
CVE-2025-58181

<2.10.2-r4
  • L
GHSA-j5w8-q4qc-rx2x

<2.10.2-r4
  • L
Unprotected Alternate Channel

<2.10.2-r3
  • L
Reachable Assertion

<2.10.2-r2
  • L
CVE-2025-47910

<2.10.2-r1
  • L
Race Condition

<2.10.0-r5
  • L
CVE-2025-22872

<2.10.0-r0
  • L
GHSA-vvgc-356p-c3xw

<2.10.0-r0
  • L
CVE-2025-22871

<2.9.1-r9
  • L
GHSA-g9pc-8g42-g6vq

<2.9.1-r9
  • L
CVE-2025-22870

<2.9.1-r7
  • L
CVE-2025-22869

<2.9.1-r6
  • L
Allocation of Resources Without Limits or Throttling

<2.9.1-r5
  • L
CVE-2025-22866

<2.9.1-r4
  • L
CVE-2024-45339

<2.9.1-r3
  • L
CVE-2024-45338

<2.8.4-r7
  • L
CVE-2024-45337

<2.8.4-r5
  • L
Insufficient Verification of Data Authenticity

<2.8.4-r4
  • L
CVE-2024-34158

<2.8.4-r3
  • L
CVE-2024-34156

<2.8.4-r3
  • L
CVE-2024-34155

<2.8.4-r3
  • L
CVE-2024-24791

<2.8.4-r2
  • M
CVE-2024-24789

<2.8.4-r1
  • C
CVE-2024-24790

<2.8.4-r1
  • L
CVE-2024-24787

<2.7.6-r9
  • L
CVE-2024-24788

<2.7.6-r9
  • L
CVE-2023-45288

<2.7.6-r8
  • L
CVE-2024-22189

<2.7.6-r6
  • L
CVE-2024-27304

<2.7.6-r4
  • L
CVE-2024-24786

<2.7.6-r4
  • L
CVE-2024-27289

<2.7.6-r4
  • L
CVE-2024-24785

<2.7.6-r3
  • L
CVE-2023-45289

<2.7.6-r3
  • L
CVE-2024-24783

<2.7.6-r3
  • L
CVE-2024-24784

<2.7.6-r3
  • L
CVE-2023-45290

<2.7.6-r3
  • M
Resource Exhaustion

<2.7.6-r2
  • M
Improper Validation of Integrity Check Value

<2.7.6-r1
  • H
Allocation of Resources Without Limits or Throttling

<2.7.5-r1
  • H
Allocation of Resources Without Limits or Throttling

<2.7.5-r0