Skip to content

Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation

High severity GitHub Reviewed Published Mar 6, 2026 in caddyserver/caddy • Updated Mar 9, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts