CVE-2026-92284
Caddy: Unbounded body buffer via {http.request.body} placeholder โ memory exhaustion DoS
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/replacer.go, resolving http.request.body reads the complete request body with an unbounded io.Copy before request-body middleware limits apply, allowing memory exhaustion and process termination.
| CWE | CWE-770 |
| Vendor | caddyserver |
| Product | caddy |
| Published | Sep 23, 2026 |
| Last Updated | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for caddyserver caddy
Be the first to know when new unknown vulnerabilities affecting caddyserver caddy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
caddyserver / caddy
<= 2.11.3