25 exploited vulnerabilities in Caddy
- Vendors
- Appsmith, Caddy, Alt Linux, Apache, Astra Linux, Haproxy
- With known exploits
- 25
- Affected Appsmith versions
- < 2.1
- Affected Caddyserver Caddy versions
- < 2.11.1, 2.11.2, 2.11.4, 2.11.3, 2.5.1, 2.4.6, 2.5.0, 0.11.0
- Affected Puma versions
- < 4.3.12, 5.6.4
- Affected Goauthentik Authentik versions
- < 2025.10.4, 2025.12.4
- Affected Haproxy Proxyprotocol versions
- < 0.0.2
- Affected Authcrunch Caddy-security versions
- = 1.1.20
- Affected Caddy Project Caddy versions
- = 2.1.4, 2.1.5, 2.1.6, 3.0.0, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.12, 6.0.1, 6.0.2, 6.0.9, 6.0.12, 6.0.14, 6.1.0, 6.2.1, 6.3.0, 6.3.1, 6.3.3, 7.0.0, 7.1.0, 7.2.7
Vulnerabilities with exploits
Highest CVSS first β each links to the exploits we have indexed
CVE-2026-55454
CVE-2026-27590
CVE-2022-24790
CVE-2026-27586
CVE-2026-27588
CVE-2026-27587
CVE-2026-50189
CVE-2026-30851
CVE-2026-25748
CVE-2026-27589
CVE-2026-27585
CVE-2026-52845
CVE-2026-45135
CVE-2026-52844
CVE-2026-30852
CVE-2022-34037
CVE-2019-14243
CVE-2026-39972
CVE-2023-52430
CVE-2022-28923
CVE-2022-29718
CVE-2017-5963
CVE-2026-45692
CVE-2018-19148
CVE-2026-52846