Loading
Generated remediation guidance and an executive summary. No account required.
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This issue has been patched in version 2.11.2.
Use CWE-287, Caddyserver vendor hub and Caddy product page to widen CVE-2026-30851 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44487, CVE-2026-27590 and CVE-2026-27586 for nearby disclosures in the same product family.