GO-2026-4644 PUBLISHED

Caddy's vars_regexp double-expands user input, leaking env vars and files in github.com/caddyserver/caddy

Affected Products

VendorProductVersions
github.comcaddyserver/caddy/v22.7.5, 2.7.5

Timeline

References

Open in Interactive Console →