CVE-2026-45692Caddyserver · Caddy
Vulnerability data via NVD (ingested)
Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves to a different config object during traversal. This happens because the authorization layer uses string prefix matching and the /config traversal layer parses array indices numerically using strconv.Atoi(). This vulnerability is fixed in 2.11.3.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-45692product:"Caddyserver Caddy"http.html:"Caddy"More intel sources (5)
vuln:CVE-2026-45692vulnerabilities.cve_id: CVE-2026-45692CVE-2026-45692CVE-2026-45692"CVE-2026-45692" exploit -site:nvd.nist.gov