Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESCADDYVERIFIED

PUBLISHER UPDATE · CADDY-2.11.1

CADDY-2.11.1 release notes and known issues

v2.11.1

Scope: Caddy. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

Our community is pleased to announce Caddy 2.11! Of note are new features, numerous bug fixes including several security patches, and various QoL ("quality-of-life") enhancements. There are no code changes from v2.11.0 other than to a CI job. Due to a recent external change that broke our release process, the first release of 2.11 is v2.11.1. Special Sponsor Shoutout Extra big thanks to our major sponsors: ZeroSSL Stripe Railway They, along with dozens of smaller sponsors, make this project and new releases possible, together with our maintainer team. Thank you all! Notable changes Encrypted ClientHello (ECH) keys are rotated automatically. Time-rolling options for logs. SIGUSR1 can now reload configuration if it was initially loaded from a file on the command line and did not get changed via the API. Reverse proxy now automatically rewrites the Host header to the address of the upstream when the upstream is HTTPS ( #7454 ) log_append can now log request and response bodies, useful for debugging. Our project now implements and requires Assistance Disclosures (for AI/LLMs) on issues, PRs, comments, replies, reviews, etc. Many, many other minor improvements and bug fixes. Thank you to everyone who was involved this release! ⚠️ Security patches fastcgi: CVE-2026-27590 by @dunglas and @AbdrrahimDahmani - Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport. admin: CVE-2026-27589 by @1seal - Cross-origin requests attempted with no-cors mode could cause some API requests to succeed; such requests are now blocked. (In order for this to be practically exploitable, a web browser executing a malicious web page must be running locally to a production Caddy process.) caddyhttp: CVE-2026-27588 by Asim Viladi Oglu Manizada - The Host matcher becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass. caddyhttp: CVE-2026-27587 by Asim Viladi Oglu Manizada - The Path matcher skips case normalization for escape sequences, enabling path-based route/auth bypass. caddytls: CVE-2026-27586 by @moscowchill - TLS client authentication silently fails open when CA certificate file is missing or malformed. caddyhttp: CVE-2026-27585 by @parrot409 - Improper sanitization of glob characters in file matcher may lead to bypassing security protections. 🚨 Notice for Caddy plugin maintainers: Dependabot will probably alert you to the security fixes in Caddy and urge you to upgrade it in your go.mod file. Please ONLY upgrade the Caddy dependency if there's a change to an exported API your plugin uses. (Then, turn Dependabot off .) What's Changed caddyhttp: add replacer placeholders for escaped values by @Qusic in #7181 AI assistance disclosure by @mholt in #7212 caddyfile: Prevent trailing space on line before env variable - Fixes #6881 by @arpansaha13 in #7215 add: encode header Content-Type graphql-response by @aro-lew in #7214 caddyhttp: Removing redundant middleware next copy by @maxcelant in #7217 build(deps): bump the all-updates group with 17 updates by @dependabot [bot] in #7236 build(deps): bump the actions-deps group with 5 updates by @dependabot [bot] in #7237 encode: fix response corruption when handle_errors is used by @Siomachkin in #7235 Fix PKI creation when auto_https is disabled ( #7211 ) by @Siomachkin in #7238 logging: Buffer the logs before config is loaded by @francislavoie in #7245 fileserver: set Content-Length for precompressed files by @WeidiDeng in #7251 refactor: use WaitGroup.Go to simplify code by @mickychang9 in #7253 caddyfile: Allow block to do nothing if nothing passed to import by @BeeJay28 in #7206 logging: Adjustments to BufferedLog to keep logs in the correct order by @francislavoie in #7257 caddyhttp: Prevent commas in header values from being split in CLI commands by @gilbsgilbs in #7268 update quic-go to v0.54.1 by @marten-seemann in #7273 chore: ugh, lint fix... by @mohammed90 in #7275 caddypki: check intermediate lif

Improvements and security content

  • Our community is pleased to announce Caddy 2.11! Of note are new features, numerous bug fixes including several security patches, and various QoL ("quality-of-life") enhancements. There are no code changes from v2.11.0 other than to a CI job. Due to a recent external change that broke our release process, the first release of 2.11 is v2.11.1. Special Sponsor Shoutout Extra big thanks to our major sponsors: ZeroSSL Stripe Railway They, along with dozens of smaller sponsors, make this project and new releases possible, together with our maintainer team. Thank you all! Notable changes Encrypted ClientHello (ECH) keys are rotated automatically. Time-rolling options for logs. SIGUSR1 can now reload configuration if it was initially loaded from a file on the command line and did not get changed via the API. Reverse proxy now automatically rewrites the Host header to the address of the upstream when the upstream is HTTPS ( #7454 ) log_append can now log request and response bodies, useful for debugging. Our project now implements and requires Assistance Disclosures (for AI/LLMs) on issues, PRs, comments, replies, reviews, etc. Many, many other minor improvements and bug fixes. Thank you to everyone who was involved this release! ⚠️ Security patches fastcgi: CVE-2026-27590 by @dunglas and @AbdrrahimDahmani - Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport. admin: CVE-2026-27589 by @1seal - Cross-origin requests attempted with no-cors mode could cause some API requests to succeed; such requests are now blocked. (In order for this to be practically exploitable, a web browser executing a malicious web page must be running locally to a production Caddy process.) caddyhttp: CVE-2026-27588 by Asim Viladi Oglu Manizada - The Host matcher becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass. caddyhttp: CVE-2026-27587 by Asim Viladi Oglu Manizada - The Path matcher skips case normalization for escape sequences, enabling path-based route/auth bypass. caddytls: CVE-2026-27586 by @moscowchill - TLS client authentication silently fails open when CA certificate file is missing or malformed. caddyhttp: CVE-2026-27585 by @parrot409 - Improper sanitization of glob characters in file matcher may lead to bypassing security protections. 🚨 Notice for Caddy plugin maintainers: Dependabot will probably alert you to the security fixes in Caddy and urge you to upgrade it in your go.mod file. Please ONLY upgrade the Caddy dependency if there's a change to an exported API your plugin uses. (Then, turn Dependabot off .) What's Changed caddyhttp: add replacer placeholders for escaped values by @Qusic in #7181 AI assistance disclosure by @mholt in #7212 caddyfile: Prevent trailing space on line before env variable - Fixes #6881 by @arpansaha13 in #7215 add: encode header Content-Type graphql-response by @aro-lew in #7214 caddyhttp: Removing redundant middleware next copy by @maxcelant in #7217 build(deps): bump the all-updates group with 17 updates by @dependabot [bot] in #7236 build(deps): bump the actions-deps group with 5 updates by @dependabot [bot] in #7237 encode: fix response corruption when handle_errors is used by @Siomachkin in #7235 Fix PKI creation when auto_https is disabled ( #7211 ) by @Siomachkin in #7238 logging: Buffer the logs before config is loaded by @francislavoie in #7245 fileserver: set Content-Length for precompressed files by @WeidiDeng in #7251 refactor: use WaitGroup.Go to simplify code by @mickychang9 in #7253 caddyfile: Allow block to do nothing if nothing passed to import by @BeeJay28 in #7206 logging: Adjustments to BufferedLog to keep logs in the correct order by @francislavoie in #7257 caddyhttp: Prevent commas in header values from being split in CLI commands by @gilbsgilbs in #7268 update quic-go to v0.54.1 by @marten-seemann in #7273 chore: ugh, lint fix... by @mohammed90 in #7275 caddypki: check intermediate lif

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Caddy

Affected versions

  • 2.11.1
  • 2.11
  • 2.11.0
  • 0.54.1

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence