← Vulnerability feed

Vulnerability record · CVE-2018-21246 · published 15 June 2020

CVE-2018-21246: Caddyserver caddy improper authentication vulnerability

Caddyserver · Caddy

Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.

9.8 CVSS 3.1 Critical EPSS 2.7% · top 14.5% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugs.gentoo.org/715214 Third Party Advisory
https://github.com/caddyserver/caddy/releases/tag/v0.10.13 Release NotesThird Party Advisory
https://bugs.gentoo.org/715214 Third Party Advisory
https://github.com/caddyserver/caddy/releases/tag/v0.10.13 Release NotesThird Party Advisory

Track CVE-2018-21246 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed8.9CVE-2026-27590Caddyserver caddy improper input validation vulnerabilityCaddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split ind…EPSS 0.86%8.8CVE-2026-30851Caddyserver caddy improper authentication vulnerabilityCaddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not str…EPSS 0.35%8.8CVE-2026-27586Caddyserver caddy vulnerabilityCaddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` …EPSS 0.40%8.1CVE-2026-52845Caddyserver caddy improper authentication vulnerabilityCaddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identit…EPSS 0.45%8.1CVE-2026-45135Caddyserver caddy improper input validation vulnerabilityCaddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/rev…EPSS 0.68%7.7CVE-2026-27588Caddyserver caddy vulnerabilityCaddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-i…EPSS 0.54%7.7CVE-2026-27587Caddyserver caddy vulnerabilityCaddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-…EPSS 0.54%

Source: NIST National Vulnerability Database (record CVE-2018-21246), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.