Threat Advisory

Caddy Vulnerability Permits Web Content Filtering Failure

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-52846 with a CVSS score of 4.2 is a flaw in the Caddy server platform caused by a bypass in the stripHTML template function. The vulnerability occurs because the function cannot reliably remove all HTML tags from input strings, allowing specially crafted malformed HTML sequences to evade the tag-stripping mechanism. An attacker can exploit this issue remotely without requiring privileges by submitting crafted payloads, such as <<>img src=x onerror=alert()>, which may cause dangerous script content to remain in the generated output. Successful exploitation could allow attackers to inject arbitrary HTML or JavaScript into web pages, leading to client-side cross-site scripting (XSS). This vulnerability may result in user session compromise, sensitive data exposure, or delivery of malicious content to website visitors. Exploitation requires an application to process untrusted input through the vulnerable stripHTML function and render the output as HTML without adequate sanitization.

RECOMMENDATIONS:

  • We recommend you to update Caddy to below version:
  • https://github.com/advisories/GHSA-vcc4-2c75-vc9v

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-52846 with a CVSS score of 4.2 is a flaw in the Caddy server platform caused by a bypass in the stripHTML template function. The vulnerability occurs because the function cannot reliably remove all HTML tags from input strings, allowing specially crafted malformed HTML sequences to evade the tag-stripping mechanism. An attacker can exploit this issue remotely without requiring privileges by submitting crafted payloads, such as <<>img src=x onerror=alert()>, which may cause dangerous script content to remain in the generated output. Successful exploitation could allow attackers to inject arbitrary HTML or JavaScript into web pages, leading to client-side cross-site scripting (XSS). This vulnerability may result in user session compromise, sensitive data exposure, or delivery of malicious content to website visitors. Exploitation requires an application to process untrusted input through the vulnerable stripHTML function and render the output as HTML without adequate sanitization.

RECOMMENDATIONS:

  • We recommend you to update Caddy to below version:
  • https://github.com/advisories/GHSA-vcc4-2c75-vc9v

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu