HIGH8.1Go
GHSA-7r4p-vjf4-gxv4· CVE-2026-30851, GO-2026-4639Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation
Modified: 3/23/2026
package
pkg:go/github.com/caddyserver/caddy/v2/modules/caddyhttp/reverseproxy
Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation
Modified: 3/23/2026