Executive brief
Caddy's vars_regexp double-expands user input, leaking env vars and files in github.com/caddyserver/caddy
Affected products
- Go github.com/caddyserver/caddy/v2
- Go github.com/caddyserver/caddy/v2/modules/caddyhttp
Junglewise Threat Intelligence
CVE-2026-30852 · Severity: medium · CVSS 4 · Published 2026-03-10
Technologies: github.com/caddyserver/caddy/v2 (Go). Vendors: Go.
Caddy's vars_regexp double-expands user input, leaking env vars and files in github.com/caddyserver/caddy