stable

caddy-2.10.2-9.el10_3

FEDORA-EPEL-2026-6f59aff531 created by carlwgeorge 3 months ago for Fedora EPEL 10.3

Security update resolving 22 CVEs across both caddy itself and its vendored libraries.

This update has been submitted for testing by carlwgeorge.

3 months ago

This update's test gating status has been changed to 'ignored'.

3 months ago

This update has been pushed to testing.

3 months ago
User Icon ephmo provided feedback 3 months ago
karma
BZ#2423203 CVE-2025-44005 caddy: github.com/smallstep/certificates: Authorization bypass allows unauthorized certificate creation [epel-all]
BZ#2441149 CVE-2025-69725 caddy: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites [epel-all]
BZ#2442422 CVE-2026-27587 caddy: Caddy: Access control bypass due to improper handling of percent-escape sequences in HTTP path matcher [epel-all]
BZ#2442424 CVE-2026-27590 caddy: Caddy: Remote Code Execution via FastCGI path confusion [epel-all]
BZ#2442428 CVE-2026-27589 caddy: Caddy: Unauthorized configuration modification via cross-origin requests to the admin API [epel-all]
BZ#2442430 CVE-2026-27586 caddy: Caddy: Authentication bypass via mTLS client certificate validation failure [epel-all]
BZ#2442435 CVE-2026-27588 caddy: Caddy: Access control bypass due to case-sensitive host matching [epel-all]
BZ#2442472 CVE-2026-27585 caddy: Caddy: Path security bypass due to unsanitized backslashes [epel-all]
BZ#2445805 CVE-2026-30851 caddy: Caddy: Privilege escalation via identity injection due to unstripped client headers [epel-all]
BZ#2445849 CVE-2026-30852 caddy: Caddy: Information disclosure via double-expansion of user-controlled input [epel-all]
BZ#2457925 CVE-2026-40097 caddy: Step CA: Denial of Service via crafted attestation key certificate [epel-all]
BZ#2458968 CVE-2026-5160 caddy: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [epel-all]
BZ#2488573 CVE-2025-47910 caddy: CrossOriginProtection bypass in net/http [epel-10]
BZ#2488574 CVE-2025-58185 caddy: Parsing DER payload can cause memory exhaustion in encoding/asn1 [epel-10]
BZ#2488577 CVE-2025-58188 caddy: Panic when validating certificates with DSA public keys in crypto/x509 [epel-10]
BZ#2488579 CVE-2025-58189 caddy: go crypto/tls ALPN negotiation error contains attacker controlled information [epel-10]
BZ#2488581 CVE-2025-61723 caddy: Quadratic complexity when parsing some invalid inputs in encoding/pem [epel-10]
BZ#2488660 CVE-2025-64702 caddy: quic-go HTTP/3 QPACK Header Expansion DoS [epel-10]
BZ#2488662 CVE-2025-47913 caddy: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [epel-10]
BZ#2489919 CVE-2026-39828 caddy: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [epel-all]
BZ#2490033 CVE-2026-39829 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [epel-all]
BZ#2490430 CVE-2026-39830 caddy: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [epel-all]

This update can be pushed to stable now if the maintainer wishes

3 months ago

This update has been submitted for stable by bodhi.

2 months ago

This update has been pushed to stable.

2 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
urgent
Karma
1
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
3 months ago
in testing
3 months ago
in stable
2 months ago
approved
3 months ago
BZ#2423203 CVE-2025-44005 caddy: github.com/smallstep/certificates: Authorization bypass allows unauthorized certificate creation [epel-all]
0
1
BZ#2441149 CVE-2025-69725 caddy: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites [epel-all]
0
1
BZ#2442422 CVE-2026-27587 caddy: Caddy: Access control bypass due to improper handling of percent-escape sequences in HTTP path matcher [epel-all]
0
1
BZ#2442424 CVE-2026-27590 caddy: Caddy: Remote Code Execution via FastCGI path confusion [epel-all]
0
1
BZ#2442428 CVE-2026-27589 caddy: Caddy: Unauthorized configuration modification via cross-origin requests to the admin API [epel-all]
0
1
BZ#2442430 CVE-2026-27586 caddy: Caddy: Authentication bypass via mTLS client certificate validation failure [epel-all]
0
1
BZ#2442435 CVE-2026-27588 caddy: Caddy: Access control bypass due to case-sensitive host matching [epel-all]
0
1
BZ#2442472 CVE-2026-27585 caddy: Caddy: Path security bypass due to unsanitized backslashes [epel-all]
0
1
BZ#2445805 CVE-2026-30851 caddy: Caddy: Privilege escalation via identity injection due to unstripped client headers [epel-all]
0
1
BZ#2445849 CVE-2026-30852 caddy: Caddy: Information disclosure via double-expansion of user-controlled input [epel-all]
0
1
BZ#2457925 CVE-2026-40097 caddy: Step CA: Denial of Service via crafted attestation key certificate [epel-all]
0
1
BZ#2458968 CVE-2026-5160 caddy: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [epel-all]
0
1
BZ#2488573 CVE-2025-47910 caddy: CrossOriginProtection bypass in net/http [epel-10]
0
1
BZ#2488574 CVE-2025-58185 caddy: Parsing DER payload can cause memory exhaustion in encoding/asn1 [epel-10]
0
1
BZ#2488577 CVE-2025-58188 caddy: Panic when validating certificates with DSA public keys in crypto/x509 [epel-10]
0
1
BZ#2488579 CVE-2025-58189 caddy: go crypto/tls ALPN negotiation error contains attacker controlled information [epel-10]
0
1
BZ#2488581 CVE-2025-61723 caddy: Quadratic complexity when parsing some invalid inputs in encoding/pem [epel-10]
0
1
BZ#2488660 CVE-2025-64702 caddy: quic-go HTTP/3 QPACK Header Expansion DoS [epel-10]
0
1
BZ#2488662 CVE-2025-47913 caddy: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [epel-10]
0
1
BZ#2489919 CVE-2026-39828 caddy: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [epel-all]
0
1
BZ#2490033 CVE-2026-39829 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [epel-all]
0
1
BZ#2490430 CVE-2026-39830 caddy: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [epel-all]
0
1

Automated Test Results