VULNERABILITY INTELLIGENCE
CVE-2026-52844
CVSS score7.5 HIGH
EPSS probability0.62%
CISA KEVNot currently listed
Published2026-06-23
Last modified2026-06-29
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as private\secret.txt on disk. An unauthenticated remote client can bypass Caddy path-scoped auth/deny routes protecting /private/*. This vulnerability is fixed in 2.11.4.
Weakness classification
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-284: Improper Access Control
Primary references
- security-advisories@github.com — Third Party Advisory, Exploit
- 134c704f-9b21-4f2e-91b3-4a467353bcc0 — Third Party Advisory, Exploit