
CVE-2026-27585 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes w… https://www.cve.org/CVERecord?id=CVE-2026-27585
Post summary
The text announces CVE-2026-27585, describing a path sanitization flaw in Caddy before v2.11.1 that fails to sanitize backslashes, but provides no PoC, exploit, or patch details.


