CVE-2026-30852Disclosure(caddyserver / caddy)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch caddyserver caddy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 double-expands user-controlled input through the Caddy replacer. When vars_regexp matches against a placeholder like {http.request.header.X-Input}, the header value gets resolved once (expected), then passed through repl.ReplaceAll() again (the bug). This means an attacker can put {env.DATABASE_URL} or {file./etc/passwd} in a request header and the server will evaluate it, leaking environment variables, file contents, and system info. This issue has been patched in version 2.11.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • caddy

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-03-07); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Products
caddy

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-07: 2Mentions · 2026-03-12: 1Mentions · 2026-05-18: 1Mentions · 2026-06-03: 1Mentions · 2026-09-18: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-06-03: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-12: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-03: 1Technical Details · 2026-09-18: 103-0703-1205-1806-0309-18
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-072
Disclosure2
2026-03-121
General1
2026-05-181
Patch1
2026-06-031
Disclosure1
2026-09-181
Disclosure1
Full discourse6 posts
  • miniMIDI Kinri@kinrimini22223
    Patch

    CVE-2026-30852 / CVSS 7.5 HIGH 修正済みバージョン: v2.11.2 - 脆弱性のタイプ: 情報漏洩 サーバーにはCaddyを使っていたのですが、人ごとではなかったようです。 参考:Nginxのリライト・バッファオーバーフロー CVE-2026-42945 / Red Hat CVSS 8.1 HIGH 更新はお早めに。 ソース⇣ https://t.co/KH5ogTngJ6

    Post summary

    The post lists two high‑severity CVEs with fix information and update advice, but does not provide exploit details or PoC references.

    20010194
    124 followersView on X
  • CyStack@CyStackSecurity
    Disclosure

    📣 ADVISORY: Researcher Trung Nguyen from @CyStackSecurity discovered a Placeholder Expansion Injection vulnerability in Caddy Web Server - bypassing CVE-2026-30852. Patch currently not available Details: https://github.com/caddyserver/caddy/security/advisories/GHSA-wwhq-w58m-w29c #CyStack #Caddy #CyberSecurity #Vulnerability https://t.co/bgaa3nVKBj

    Post summary

    The advisory announces a new Placeholder Expansion Injection vulnerability in Caddy that bypasses CVE‑2026‑30852, provides technical details, but no PoC, exploit code, or patch is available at this time.

    0001055
    3.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30852 Information Disclosure Vulnerability in Caddy Server Replacer Mechanism https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30852

    Post summary

    CVE-2026-30852 is reported as an information disclosure issue in Caddy Server’s replacer mechanism, with no associated PoC, exploit code, active exploitation, or patch details mentioned.

    0001063
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Caddy v2113, Multiple Handler/Placeholder Vulnerabilities, #CVE-2026-30852 (Same Bug Class) (Low/Moderate) -DC-Sep2026-2473 https://dailycve.com/caddy-v2113-multiple-handler-placeholder-vulnerabilities-cve-2026-30852-same-bug-class-low-moderate-dc-sep2026-2473/

    Post summary

    A brief disclosure post announcing multiple handler/placeholder vulnerabilities in Caddy v2113 (CVE-2026-30852), rated Low/Moderate severity, linking to a DailyCVE summary for further details.

    0000036
    237 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-30852 (CVSS:5.5, HIGH) is Analyzed. Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_r..https://nvd.nist.gov/vuln/detail/CVE-2026-30852 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post briefly notes that CVE‑2026‑30852, a high‑CVSS vulnerability affecting Caddy v2.7.5‑v2.11.2, has been analyzed, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000023
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30852 Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 double-expands us… https://www.cve.org/CVERecord?id=CVE-2026-30852

    Post summary

    The excerpt delivers a brief disclosure of CVE‑2026‑30852, noting the affected Caddy server versions and a specific double‑expansion flaw in vars.go, but does not provide exploit details, active attack reports, or remediation guidance.

    0000083
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcaddyservercaddy---

Explore more