{"api_version":"v1","generated_at":"2026-10-07T11:00:00+00:00","product":{"cve_count":16,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-caddyserver-caddy-7bcdc65de08c","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/caddy","name":"caddy","next_cursor":null,"observations":[{"affected":"caddy: <= 2.11.3","affected_versions_present":true,"cve_id":"CVE-2026-92700","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-92700","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-23T19:23:08.504Z","patch_url":"","primary_source":"","published":"2026-09-23T17:58:45.844Z"},{"affected":"caddy: <= 2.11.3","affected_versions_present":true,"cve_id":"CVE-2026-92284","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-92284","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-23T19:21:14.152Z","patch_url":"","primary_source":"","published":"2026-09-23T17:58:42.789Z"},{"affected":"caddy: < 2.11.4","affected_versions_present":true,"cve_id":"CVE-2026-77281","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77281","fixed":"2.11.4.","last_modified":"2026-09-18T14:43:34.818Z","patch_url":"https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9","primary_source":"","published":"2026-09-17T21:04:58.400Z"},{"affected":">= 2.7.0, < 2.11.3","affected_versions_present":true,"cve_id":"CVE-2026-45135","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45135","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-23T18:30:27.933Z","patch_url":"","primary_source":"","published":"2026-06-23T17:56:42.662Z"},{"affected":">= 2.4.0, < 2.11.3","affected_versions_present":true,"cve_id":"CVE-2026-45692","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45692","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-26T18:16:37.211Z","patch_url":"","primary_source":"","published":"2026-06-23T17:55:11.317Z"},{"affected":"< 2.11.4","affected_versions_present":true,"cve_id":"CVE-2026-52845","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-52845","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T00:46:09.498Z","patch_url":"","primary_source":"","published":"2026-06-23T17:52:01.871Z"},{"affected":"< 2.11.4","affected_versions_present":true,"cve_id":"CVE-2026-52844","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-52844","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-23T20:06:12.019Z","patch_url":"","primary_source":"","published":"2026-06-23T17:50:42.386Z"},{"affected":"< 2.11.4","affected_versions_present":true,"cve_id":"CVE-2026-52846","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-52846","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-25T12:42:16.519Z","patch_url":"","primary_source":"","published":"2026-06-23T17:47:30.387Z"},{"affected":">= 2.10.0, < 2.11.2","affected_versions_present":true,"cve_id":"CVE-2026-30851","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-30851","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-09T18:24:49.691Z","patch_url":"https://github.com/caddyserver/caddy/security/advisories/GHSA-7r4p-vjf4-gxv4","primary_source":"","published":"2026-03-07T16:28:37.097Z"},{"affected":">= 2.7.5, < 2.11.2","affected_versions_present":true,"cve_id":"CVE-2026-30852","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-30852","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-09T18:24:55.495Z","patch_url":"https://github.com/caddyserver/caddy/pull/5408","primary_source":"","published":"2026-03-07T16:28:26.894Z"},{"affected":"< 2.11.1","affected_versions_present":true,"cve_id":"CVE-2026-27590","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27590","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-27T20:52:00.327Z","patch_url":"","primary_source":"","published":"2026-02-24T16:33:41.353Z"},{"affected":"< 2.11.1","affected_versions_present":true,"cve_id":"CVE-2026-27589","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27589","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-27T20:51:24.110Z","patch_url":"https://github.com/caddyserver/caddy/security/advisories/GHSA-879p-475x-rqh2","primary_source":"","published":"2026-02-24T16:30:52.016Z"},{"affected":"< 2.11.1","affected_versions_present":true,"cve_id":"CVE-2026-27588","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27588","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-27T20:47:36.164Z","patch_url":"","primary_source":"","published":"2026-02-24T16:28:28.106Z"},{"affected":"< 2.11.1","affected_versions_present":true,"cve_id":"CVE-2026-27587","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27587","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-27T20:48:09.775Z","patch_url":"","primary_source":"","published":"2026-02-24T16:26:40.222Z"},{"affected":"< 2.11.1","affected_versions_present":true,"cve_id":"CVE-2026-27586","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27586","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-26T20:56:20.526Z","patch_url":"","primary_source":"","published":"2026-02-24T16:08:20.569Z"},{"affected":"< 2.11.1","affected_versions_present":true,"cve_id":"CVE-2026-27585","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27585","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-26T21:17:36.422Z","patch_url":"","primary_source":"","published":"2026-02-24T16:06:05.030Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"caddyserver"}}
