VDB
Sign up
—

GO-2026-4639

Caddy forward_auth copy_headers allows Identity Injection and Privilege Escalation in github.com/caddyserver/caddy

Quick fix

GO-2026-4639 — github.com/caddyserver/caddy/v2: upgrade to the fixed version with the command below.

go get github.com/caddyserver/caddy/v2@v2.11.2

Details

Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation in github.com/caddyserver/caddy

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/caddyserver/caddy/v2
Introduced in: 2.10.0Fixed in: 2.11.2
Fixgo get github.com/caddyserver/caddy/v2@v2.11.2

References