Vulnerability Report: GO-2026-4644

Caddy's vars_regexp double-expands user input, leaking env vars and files in github.com/caddyserver/caddy

For detailed information about this vulnerability, visit https://github.com/caddyserver/caddy/security/advisories/GHSA-m2w3-8f23-hxxf.

Affected Packages

Aliases

References

Feedback

See anything missing or incorrect? Suggest an edit to this report.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL