CVE-2026-27585Disclosure(caddyserver / caddy)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Version 2.11.1 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • caddy

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-25)
  • 3 total mentions across 2 days

Affected systems

Products
caddy

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-24: 1Mentions · 2026-02-25: 2Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 202-2402-25
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-241
Disclosure1
2026-02-252
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27585 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes w… https://www.cve.org/CVERecord?id=CVE-2026-27585

    Post summary

    The text announces CVE-2026-27585, describing a path sanitization flaw in Caddy before v2.11.1 that fails to sanitize backslashes, but provides no PoC, exploit, or patch details.

    00000144
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27585: Backslash Blues: Bypassing Caddy's ACLs with a Single Character A semantic gap between Caddy's HTTP request matching and the underlying Go filesystem globbing logic allows attackers to bypass path-based access controls. By injecting ba... https://cvereports.com/reports/CVE-2026-27585

    Post summary

    The report highlights a semantic gap in Caddy that permits path-based ACL bypass via a single character injection, but it does not provide a PoC, exploit code, or patch information.

    0000036
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27585 Path Traversal Vulnerability in Caddy Web Server Prior to Version... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27585 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post announces a path traversal vulnerability (CVE‑2026‑27585) affecting Caddy Web Server, with technical details and a link to further information.

    0000045
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcaddyservercaddy---

Explore more