MEDIUM 6.3 NVD
CVE-2026-92700
Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() use
Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() uses case-sensitive filepath.Match checks, so case variants can bypass hide rules on case-insensitive filesystems or when mixed-case paths coexist and expose files intended to be hidden.
References
- https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9
- https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-09-23 via NVD.
vulnfeed aggregates 12908 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.