Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-52844

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Jun 23, 2026
Vendor unknown

Description

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as private\secret.txt on disk. An unauthenticated remote client can bypass Caddy path-scoped auth/deny routes protecting /private/*. This vulnerability is fixed in 2.11.4.

References