-
Notifications
You must be signed in to change notification settings - Fork 177
Open
Description
While working on this project, I identified CVE-2026-27589 affecting the Caddy web server. The vulnerability allows cross-origin configuration manipulation through the local admin API when origin enforcement is not enabled. An attacker could send a malicious POST request to the /load endpoint and replace the running configuration, potentially altering server behavior and exposing sensitive data.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels