-
-
Notifications
You must be signed in to change notification settings - Fork 4.6k
Closed as duplicate of#7384
Description
Issue Details
The latest stable release (2.10.2) still pulls in the vulnerable github.com/smallstep/certificates dependency. Details here.
The fix is already available on the main branch: 8a87bb3
Is a security release 2.10.3 required or is this vulnerability not exploitable in caddy? Thanks for clarifying this.
Assistance Disclosure
AI not used
If AI was used, describe the extent to which it was used.
No response
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels