VDB
GO-2026-4535
GO-2026-4535
PUBLISHED
Improper sanitization of glob characters in github.com/caddyserver/caddy/v2
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | caddyserver/caddy/v2 | 0, 0 |
Timeline
- Feb 26, 2026 CVE Published
- Feb 26, 2026 CVE Updated
References
- https://github.com/caddyserver/caddy/security/advisories/GHSA-4xrr-hq4w-6vf4 advisory
- https://caddyserver.com/docs/caddyfile/directives#directive-order url
- https://github.com/caddyserver/caddy/blob/68d50020eef0d4c3398b878f17c8092ca5b58ca0/modules/caddyhttp/fileserver/matcher.go#L361 url
- https://github.com/caddyserver/caddy/blob/68d50020eef0d4c3398b878f17c8092ca5b58ca0/modules/caddyhttp/fileserver/matcher.go#L398 url
- https://github.com/caddyserver/caddy/releases/tag/v2.11.1 url