{"id":"GO-2026-6512","summary":"Vulnerabilities in handler/placeholder layer in github.com/caddyserver/caddy","details":"Rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass in github.com/caddyserver/caddy","aliases":["CVE-2026-77281","CVE-2026-92284","CVE-2026-92700","GHSA-j8px-rmrx-76h9"],"modified":"2026-10-01T20:55:47.886275070Z","published":"2026-10-01T20:23:42Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-6512","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9"},{"type":"FIX","url":"https://github.com/caddyserver/caddy/commit/176b043b0104cee3f894023cd5a598ac29e404bb"},{"type":"FIX","url":"https://github.com/caddyserver/caddy/pull/7761"},{"type":"WEB","url":"https://github.com/caddyserver/caddy/releases/tag/v2.11.4"}],"affected":[{"package":{"name":"github.com/caddyserver/caddy/v2","ecosystem":"Go","purl":"pkg:golang/github.com/caddyserver/caddy/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.11.4"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/caddyserver/caddy/v2/modules/caddyhttp/rewrite","symbols":["Rewrite.Provision","Rewrite.Rewrite","Rewrite.ServeHTTP","queryOpsReplacement.Provision"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6512.json"}}],"schema_version":"1.9.0"}