Junglewise Threat Intelligence

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching

Severity: low · CVSS 3.1 · Published 2026-05-19

Technologies: github.com/caddyserver/caddy/v2 (Go). Vendors: Go.

Executive brief

Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching

Affected products

  • Go github.com/caddyserver/caddy/v2

Related threats