—
GO-2026-4639
Caddy forward_auth copy_headers allows Identity Injection and Privilege Escalation in github.com/caddyserver/caddy
Quick fix
GO-2026-4639 — github.com/caddyserver/caddy/v2: upgrade to the fixed version with the command below.
go get github.com/caddyserver/caddy/v2@v2.11.2Details
Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation in github.com/caddyserver/caddy
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/caddyserver/caddy/v2
Introduced in:
2.10.0Fixed in: 2.11.2Fix
go get github.com/caddyserver/caddy/v2@v2.11.2