CVE-2026-30851
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forwardauth copyheaders does not strip client-supplied headers, allowing identity injection and privilege escalation. This issue has been patched in version 2.11.2.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30851.json, https://github.com/caddyserver/caddy/security/advisories/GHSA-7r4p-vjf4-gxv4, https://nvd.nist.gov/vuln/detail/CVE-2026-30851, https://github.com/caddyserver/caddy/issues/6610, https://github.com/caddyserver/caddy/pull/6608, https://github.com/caddyserver/caddy/pull/7545
