CVE-2026-30851Disclosure(caddyserver / caddy)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This issue has been patched in version 2.11.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-345

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • caddy

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-07); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
caddy

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-12: 1Mentions · 2026-03-18: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-18: 103-0703-0803-1203-18
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Zexuan Luo@spacewander_lzx
    Disclosure

    https://www.miggo.io/vulnerability-database/cve/CVE-2026-30851 这个漏洞有个模式: 1. 用户配置proxy,将auth server返回的x设置成header y传递给上游 2. 关键一步:auth server没有返回x,如果proxy不会清空header y,这时候传给上游的是client发过来的header y (1/2)

    Post summary

    The entry outlines the vulnerability scenario for CVE‑2026‑30851, explaining how a proxy can inadvertently forward a header that should be set by an authentication server, potentially exposing sensitive data.

    101311.5K
    6.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30851 - High Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing ident... https://www.thehackerwire.com/vulnerability/CVE-2026-30851/ https://t.co/wU7yY4MhQk

    Post summary

    The text announces a high‑severity CVE in Caddy, detailing improper header handling, but does not provide PoC, exploit, or patch information.

    0000137
    130 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-30851 (CVSS:8.1, HIGH) is Analyzed. Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_a..https://nvd.nist.gov/vuln/detail/CVE-2026-30851 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE‑2026‑30851 is highlighted with a CVSS score of 8.1, affecting Caddy versions 2.10.0 through 2.11.1; no exploitation or patch details are provided.

    0000025
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30851 Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplie… https://www.cve.org/CVERecord?id=CVE-2026-30851

    Post summary

    The excerpt announces CVE-2026-30851, describing a flaw in Caddy's forward_auth copy_headers function affecting versions 2.10.0 through 2.11.2, but does not provide proof, exploitation details, or remediation guidance.

    0000078
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcaddyservercaddy---

Explore more