Repository navigation
fix(oci/library/caddy): update 2.11.2 ➼ 2.11.7 - #5759
Open
tinfoild[bot] wants to merge 1 commit into
Open
tinfoild[bot] wants to merge 1 commit into
tinfoild[bot] wants to merge 1 commit into
Conversation
Contributor
Author
kube/helmrelease/out00--- HelmRelease: rook-ceph/rgw Deployment: rook-ceph/rgw
+++ HelmRelease: rook-ceph/rgw Deployment: rook-ceph/rgw
@@ -60,13 +60,13 @@
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: DoNotSchedule
containers:
- env:
- name: TZ
value: null
- image: public.ecr.aws/docker/library/caddy:2.11.2-alpine@sha256:fce4f15aad23222c0ac78a1220adf63bae7b94355d5ea28eee53910624acedfa
+ image: public.ecr.aws/docker/library/caddy:2.11.7-alpine@sha256:d8542f48d34a9cf4e4c11a478865229840e87e4c96ea3f439101f31a5d35f75f
livenessProbe:
failureThreshold: 3
initialDelaySeconds: 0
periodSeconds: 10
tcpSocket:
port: 80 |
tinfoild
Bot
force-pushed
the
renovate/public.ecr.aws-docker-library-caddy-2.11.x
branch
2 times, most recently
from
May 15, 2026 18:39
9319c35 to
da267f9
Compare
tinfoild
Bot
force-pushed
the
renovate/public.ecr.aws-docker-library-caddy-2.11.x
branch
from
June 3, 2026 19:26
da267f9 to
84447db
Compare
tinfoild
Bot
force-pushed
the
renovate/public.ecr.aws-docker-library-caddy-2.11.x
branch
from
June 3, 2026 21:15
84447db to
e5db534
Compare
Contributor
Author
kube/kustomization/out00--- kube/deploy/core/storage/rook-ceph/cluster/biohazard Kustomization: flux-system/1-core-storage-rook-ceph-cluster HelmRelease: rook-ceph/rgw
+++ kube/deploy/core/storage/rook-ceph/cluster/biohazard Kustomization: flux-system/1-core-storage-rook-ceph-cluster HelmRelease: rook-ceph/rgw
@@ -58,13 +58,13 @@
containers:
main:
env:
TZ: null
image:
repository: public.ecr.aws/docker/library/caddy
- tag: 2.11.2-alpine@sha256:fce4f15aad23222c0ac78a1220adf63bae7b94355d5ea28eee53910624acedfa
+ tag: 2.11.4-alpine@sha256:6aeddd44c3078b0f9a35206472a11420648a79c184603ef95957d0a20044cb2b
probes:
liveness:
enabled: true
readiness:
enabled: true
resources: |
tinfoild
Bot
force-pushed
the
renovate/public.ecr.aws-docker-library-caddy-2.11.x
branch
2 times, most recently
from
June 8, 2026 20:58
d3e54e8 to
8a276df
Compare
tinfoild
Bot
force-pushed
the
renovate/public.ecr.aws-docker-library-caddy-2.11.x
branch
4 times, most recently
from
June 24, 2026 07:18
c96f1be to
58eceb2
Compare
tinfoild
Bot
force-pushed
the
renovate/public.ecr.aws-docker-library-caddy-2.11.x
branch
from
July 20, 2026 10:10
58eceb2 to
d35e942
Compare
Contributor
|
SECURITY VULNERABILITIES FOUND BY CIEL
Severity Summary
ResultsPackage:
|
| Finding | Severity | Reason not applicable |
|---|---|---|
| CVE-2026-27585..27590 (6 CVEs) | CRITICAL/HIGH/MEDIUM | All fixed in Caddy 2.11.1; both 2.11.2 and 2.11.4 are newer |
| CVE-2026-30851, CVE-2026-30852 | HIGH | Fixed in 2.11.2; neither version is affected |
| CVE-2026-52844 | HIGH (7.5) | Windows-only backslash bypass; deployment runs Alpine Linux |
| CVE-2022-29718, CVE-2022-28923 | MEDIUM | Open redirect in v2.4; fixed long before 2.11.x |
| CVE-2018-19148, CVE-2018-21246 | CRITICAL/LOW | Affects Caddy ≤0.11; both versions are 2.11.x |
| CVE-2023-45084 | HIGH | SoftIron HyperCloud hardware — different product entirely |
Changelog Security Highlights (2.11.2 → 2.11.4)
- v2.11.3 — Fixes CVE-2026-45135 (FastCGI Unicode splitPos RCE) and CVE-2026-45692 (admin API config traversal)
- v2.11.3 — Fixes forward_auth identity injection (CVE-2026-30851) and vars_regexp double-expansion (CVE-2026-30852) — though these were not in scope as already fixed in 2.11.2
- v2.11.4 — Fixes CVE-2026-52844 (Windows backslash path bypass), CVE-2026-52845 (forward_auth underscore header injection), CVE-2026-52846 (stripHTML XSS)
- v2.11.4 — Additional hardening: Windows backslash normalization, placeholder re-expansion prevention, underscore header field ignoring, admin array index/path auth hardening
- Built on Go 1.26.1+ — inherits Go runtime security patches
Recommendations
- MERGE PRIORITY: HIGH — The old version (2.11.2) has 2 HIGH and 2 MEDIUM-severity vulnerabilities, all remediated in 2.11.4. No new vulnerabilities introduced.
- Assessment: This patch-level update is small and safe — Caddy 2.11.4 is the latest 2.11.x release and fixes all known CVEs in the 2.11 series.
- Action required: Merge this PR to close the security gap. No config changes needed.
- MERGE ASAP — CVE-2026-45145 (FastCGI RCE) is the most concerning finding; if the deployment uses FastCGI (PHP), it is at risk.
⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.
tinfoild
Bot
force-pushed
the
renovate/public.ecr.aws-docker-library-caddy-2.11.x
branch
3 times, most recently
from
September 23, 2026 06:15
670f186 to
a09de9d
Compare
tinfoild
Bot
force-pushed
the
renovate/public.ecr.aws-docker-library-caddy-2.11.x
branch
from
October 2, 2026 23:08
a09de9d to
9f22ebb
Compare
tinfoild
Bot
force-pushed
the
renovate/public.ecr.aws-docker-library-caddy-2.11.x
branch
2 times, most recently
from
October 5, 2026 22:50
8d0a94c to
e23ca6b
Compare
tinfoild
Bot
force-pushed
the
renovate/public.ecr.aws-docker-library-caddy-2.11.x
branch
from
October 6, 2026 10:36
e23ca6b to
b058f94
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.11.2-alpine→2.11.7-alpineWarning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Configuration
📅 Schedule: (in timezone Asia/Singapore)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate.