← Vulnerability feed

Vulnerability record · CVE-2026-30851 · published 7 March 2026

CVE-2026-30851: Caddyserver caddy improper authentication vulnerability

Caddyserver · Caddy

Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This issue has been patched in version 2.11.2.

8.8 CVSS 3.1 High EPSS 0.35% · top 74.3% CWE-287 · Improper authenticationCWE-345 · Insufficient verification of data authenticity
8.8CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This issue has been patched in version 2.11.2.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-30851 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2018-21246Caddyserver caddy improper authentication vulnerabilityCaddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching m…EPSS 2.7%8.9CVE-2026-27590Caddyserver caddy improper input validation vulnerabilityCaddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split ind…EPSS 0.86%8.8CVE-2026-27586Caddyserver caddy vulnerabilityCaddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` …EPSS 0.40%8.1CVE-2026-52845Caddyserver caddy improper authentication vulnerabilityCaddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identit…EPSS 0.45%8.1CVE-2026-45135Caddyserver caddy improper input validation vulnerabilityCaddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/rev…EPSS 0.68%7.7CVE-2026-27588Caddyserver caddy vulnerabilityCaddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-i…EPSS 0.54%7.7CVE-2026-27587Caddyserver caddy vulnerabilityCaddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-…EPSS 0.54%

Source: NIST National Vulnerability Database (record CVE-2026-30851), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.