Loading
Generated remediation guidance and an executive summary. No account required.
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
Use CWE-287, Caddyserver vendor hub and Caddy product page to widen CVE-2018-21246 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44487, CVE-2026-27590 and CVE-2026-27586 for nearby disclosures in the same product family.