Junglewise Threat Intelligence

CVE-2026-30852: GO-2026-4644 - Caddy's vars_regexp double-expands user input, leaking env vars and files in github.com/caddyserver/caddy

CVE-2026-30852 · Severity: medium · CVSS 4 · Published 2026-03-10

Technologies: github.com/caddyserver/caddy/v2 (Go). Vendors: Go.

Executive brief

Caddy's vars_regexp double-expands user input, leaking env vars and files in github.com/caddyserver/caddy

Affected products

  • Go github.com/caddyserver/caddy/v2
  • Go github.com/caddyserver/caddy/v2/modules/caddyhttp

Related threats