Skip to content

CVE-2025-44005 #7420

@toxeus

Description

@toxeus

Issue Details

The latest stable release (2.10.2) still pulls in the vulnerable github.com/smallstep/certificates dependency. Details here.

The fix is already available on the main branch: 8a87bb3

Is a security release 2.10.3 required or is this vulnerability not exploitable in caddy? Thanks for clarifying this.

Assistance Disclosure

AI not used

If AI was used, describe the extent to which it was used.

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions