stable

caddy-2.10.2-9.fc43

FEDORA-2026-3dc324bd9a created by carlwgeorge a month ago for Fedora 43

Security update resolving 22 CVEs across both caddy itself and its vendored libraries.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-3dc324bd9a

This update has been submitted for testing by carlwgeorge.

a month ago

This update's test gating status has been changed to 'ignored'.

a month ago

This update has been pushed to testing.

a month ago

This update has been submitted for stable by bodhi.

a month ago
User Icon ephmo provided feedback a month ago
karma
BZ#2488094 CVE-2026-30851 caddy: Caddy: Privilege escalation via identity injection due to unstripped client headers [fedora-all]
BZ#2488095 CVE-2026-30852 caddy: Caddy: Information disclosure via double-expansion of user-controlled input [fedora-all]
BZ#2488141 CVE-2026-40097 caddy: Step CA: Denial of Service via crafted attestation key certificate [fedora-all]
BZ#2488502 CVE-2026-27585 caddy: Caddy: Path security bypass due to unsanitized backslashes [fedora-all]
BZ#2488503 CVE-2026-27586 caddy: Caddy: Authentication bypass via mTLS client certificate validation failure [fedora-all]
BZ#2488514 CVE-2026-27587 caddy: Caddy: Access control bypass due to improper handling of percent-escape sequences in HTTP path matcher [fedora-all]
BZ#2488516 CVE-2026-27588 caddy: Caddy: Access control bypass due to case-sensitive host matching [fedora-all]
BZ#2488517 CVE-2026-27589 caddy: Caddy: Unauthorized configuration modification via cross-origin requests to the admin API [fedora-all]
BZ#2488518 CVE-2026-27590 caddy: Caddy: Remote Code Execution via FastCGI path confusion [fedora-all]
BZ#2488572 CVE-2025-47910 caddy: CrossOriginProtection bypass in net/http [fedora-43]
BZ#2488575 CVE-2025-58185 caddy: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43]
BZ#2488578 CVE-2025-58188 caddy: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43]
BZ#2488580 CVE-2025-58189 caddy: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43]
BZ#2488582 CVE-2025-61723 caddy: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43]
BZ#2488661 CVE-2025-64702 caddy: quic-go HTTP/3 QPACK Header Expansion DoS [fedora-all]
BZ#2488663 CVE-2025-47913 caddy: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-all]
BZ#2488665 CVE-2025-44005 caddy: github.com/smallstep/certificates: Authorization bypass allows unauthorized certificate creation [fedora-all]
BZ#2488666 CVE-2025-69725 caddy: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites [fedora-all]
BZ#2488667 CVE-2026-5160 caddy: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [fedora-all]
BZ#2489962 CVE-2026-39828 caddy: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
BZ#2490067 CVE-2026-39829 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
BZ#2490486 CVE-2026-39830 caddy: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]

This update has been pushed to stable.

a month ago

Please log in to add feedback.

Metadata
Type
security
Severity
urgent
Karma
1
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
a month ago
in testing
a month ago
in stable
a month ago
approved
a month ago
BZ#2488094 CVE-2026-30851 caddy: Caddy: Privilege escalation via identity injection due to unstripped client headers [fedora-all]
0
1
BZ#2488095 CVE-2026-30852 caddy: Caddy: Information disclosure via double-expansion of user-controlled input [fedora-all]
0
1
BZ#2488141 CVE-2026-40097 caddy: Step CA: Denial of Service via crafted attestation key certificate [fedora-all]
0
1
BZ#2488502 CVE-2026-27585 caddy: Caddy: Path security bypass due to unsanitized backslashes [fedora-all]
0
1
BZ#2488503 CVE-2026-27586 caddy: Caddy: Authentication bypass via mTLS client certificate validation failure [fedora-all]
0
1
BZ#2488514 CVE-2026-27587 caddy: Caddy: Access control bypass due to improper handling of percent-escape sequences in HTTP path matcher [fedora-all]
0
1
BZ#2488516 CVE-2026-27588 caddy: Caddy: Access control bypass due to case-sensitive host matching [fedora-all]
0
1
BZ#2488517 CVE-2026-27589 caddy: Caddy: Unauthorized configuration modification via cross-origin requests to the admin API [fedora-all]
0
1
BZ#2488518 CVE-2026-27590 caddy: Caddy: Remote Code Execution via FastCGI path confusion [fedora-all]
0
1
BZ#2488572 CVE-2025-47910 caddy: CrossOriginProtection bypass in net/http [fedora-43]
0
1
BZ#2488575 CVE-2025-58185 caddy: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43]
0
1
BZ#2488578 CVE-2025-58188 caddy: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43]
0
1
BZ#2488580 CVE-2025-58189 caddy: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43]
0
1
BZ#2488582 CVE-2025-61723 caddy: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43]
0
1
BZ#2488661 CVE-2025-64702 caddy: quic-go HTTP/3 QPACK Header Expansion DoS [fedora-all]
0
1
BZ#2488663 CVE-2025-47913 caddy: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-all]
0
1
BZ#2488665 CVE-2025-44005 caddy: github.com/smallstep/certificates: Authorization bypass allows unauthorized certificate creation [fedora-all]
0
1
BZ#2488666 CVE-2025-69725 caddy: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites [fedora-all]
0
1
BZ#2488667 CVE-2026-5160 caddy: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [fedora-all]
0
1
BZ#2489962 CVE-2026-39828 caddy: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
0
1
BZ#2490067 CVE-2026-39829 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
0
1
BZ#2490486 CVE-2026-39830 caddy: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
0
1

Automated Test Results