THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-j8px-rmrx-76h9 (medium) — Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass

[GHSA] GHSA-j8px-rmrx-76h9 (medium) — Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass

medgithub_advisoriesPublished 2026-09-18

GHSA-j8px-rmrx-76h9 Severity: medium CVE: CVE-2026-77281

Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass

# Caddy v2.11.3 — Three vulnerabilities in handler/placeholder layer

**Tested against:** `caddy:2.11.3` (official Docker image, SHA verified at runtime) **Reproduction environment:** Docker Desktop 4.73.1 / Engine 29.4.3 on Windows 1

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-j8px-rmrx-76h9