Skip to content

fix(oci/library/caddy): update 2.11.2 ➼ 2.11.7 - #5759

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/public.ecr.aws-docker-library-caddy-2.11.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/public.ecr.aws-docker-library-caddy-2.11.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented May 13, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
public.ecr.aws/docker/library/caddy (source) patch 2.11.2-alpine → 2.11.7-alpine OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented May 13, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: b058f94
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented May 13, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: rook-ceph/rgw Deployment: rook-ceph/rgw

+++ HelmRelease: rook-ceph/rgw Deployment: rook-ceph/rgw

@@ -60,13 +60,13 @@

         topologyKey: kubernetes.io/hostname
         whenUnsatisfiable: DoNotSchedule
       containers:
       - env:
         - name: TZ
           value: null
-        image: public.ecr.aws/docker/library/caddy:2.11.2-alpine@sha256:fce4f15aad23222c0ac78a1220adf63bae7b94355d5ea28eee53910624acedfa
+        image: public.ecr.aws/docker/library/caddy:2.11.7-alpine@sha256:d8542f48d34a9cf4e4c11a478865229840e87e4c96ea3f439101f31a5d35f75f
         livenessProbe:
           failureThreshold: 3
           initialDelaySeconds: 0
           periodSeconds: 10
           tcpSocket:
             port: 80

@tinfoild
tinfoild Bot force-pushed the renovate/public.ecr.aws-docker-library-caddy-2.11.x branch 2 times, most recently from 9319c35 to da267f9 Compare May 15, 2026 18:39
@tinfoild
tinfoild Bot force-pushed the renovate/public.ecr.aws-docker-library-caddy-2.11.x branch from da267f9 to 84447db Compare June 3, 2026 19:26
@tinfoild tinfoild Bot changed the title fix(oci/library/caddy): update 2.11.2 ➼ 2.11.3 fix(oci/library/caddy): update 2.11.2 ➼ 2.11.4 Jun 3, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/public.ecr.aws-docker-library-caddy-2.11.x branch from 84447db to e5db534 Compare June 3, 2026 21:15
@tinfoild

tinfoild Bot commented Jun 3, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/storage/rook-ceph/cluster/biohazard Kustomization: flux-system/1-core-storage-rook-ceph-cluster HelmRelease: rook-ceph/rgw

+++ kube/deploy/core/storage/rook-ceph/cluster/biohazard Kustomization: flux-system/1-core-storage-rook-ceph-cluster HelmRelease: rook-ceph/rgw

@@ -58,13 +58,13 @@

         containers:
           main:
             env:
               TZ: null
             image:
               repository: public.ecr.aws/docker/library/caddy
-              tag: 2.11.2-alpine@sha256:fce4f15aad23222c0ac78a1220adf63bae7b94355d5ea28eee53910624acedfa
+              tag: 2.11.4-alpine@sha256:6aeddd44c3078b0f9a35206472a11420648a79c184603ef95957d0a20044cb2b
             probes:
               liveness:
                 enabled: true
               readiness:
                 enabled: true
             resources:

@tinfoild
tinfoild Bot force-pushed the renovate/public.ecr.aws-docker-library-caddy-2.11.x branch 2 times, most recently from d3e54e8 to 8a276df Compare June 8, 2026 20:58
@tinfoild
tinfoild Bot force-pushed the renovate/public.ecr.aws-docker-library-caddy-2.11.x branch 4 times, most recently from c96f1be to 58eceb2 Compare June 24, 2026 07:18
@tinfoild
tinfoild Bot force-pushed the renovate/public.ecr.aws-docker-library-caddy-2.11.x branch from 58eceb2 to d35e942 Compare July 20, 2026 10:10
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 07:44 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5759 — fix(oci/library/caddy): update 2.11.2 ➼ 2.11.4
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 4 (applicable to the Caddy server in this deployment)


Severity Summary

Severity Count
CRITICAL 0
HIGH 2
MEDIUM / MODERATE 2
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 4

Results

Package: public.ecr.aws/docker/library/caddy

  • Ecosystem: Docker (Go-based web server)
  • Base image: caddy:2.11.2-alpine → caddy:2.11.4-alpine (official Caddy Docker images on Alpine Linux)
  • Old version: 2.11.2 — VULNERABLE (4 CVEs: 2 HIGH, 2 MEDIUM)
  • New version: 2.11.4 — CLEAN

Vulnerabilities in version 2.11.2 (old version only — all fixed in 2.11.3 or 2.11.4)

  1. CVE-2026-45135 — Severity: HIGH (CVSS 8.1)

  2. CVE-2026-52845 — Severity: HIGH (CVSS 8.1)

  3. CVE-2026-45692 — Severity: MEDIUM (CVSS 5.4)

  4. CVE-2026-52846 — Severity: MEDIUM (CVSS 4.2)

Vulnerabilities in version 2.11.4

No known vulnerabilities found.

Non-applicable findings (verified and excluded)

Finding Severity Reason not applicable
CVE-2026-27585..27590 (6 CVEs) CRITICAL/HIGH/MEDIUM All fixed in Caddy 2.11.1; both 2.11.2 and 2.11.4 are newer
CVE-2026-30851, CVE-2026-30852 HIGH Fixed in 2.11.2; neither version is affected
CVE-2026-52844 HIGH (7.5) Windows-only backslash bypass; deployment runs Alpine Linux
CVE-2022-29718, CVE-2022-28923 MEDIUM Open redirect in v2.4; fixed long before 2.11.x
CVE-2018-19148, CVE-2018-21246 CRITICAL/LOW Affects Caddy ≤0.11; both versions are 2.11.x
CVE-2023-45084 HIGH SoftIron HyperCloud hardware — different product entirely

Changelog Security Highlights (2.11.2 → 2.11.4)

  • v2.11.3 — Fixes CVE-2026-45135 (FastCGI Unicode splitPos RCE) and CVE-2026-45692 (admin API config traversal)
  • v2.11.3 — Fixes forward_auth identity injection (CVE-2026-30851) and vars_regexp double-expansion (CVE-2026-30852) — though these were not in scope as already fixed in 2.11.2
  • v2.11.4 — Fixes CVE-2026-52844 (Windows backslash path bypass), CVE-2026-52845 (forward_auth underscore header injection), CVE-2026-52846 (stripHTML XSS)
  • v2.11.4 — Additional hardening: Windows backslash normalization, placeholder re-expansion prevention, underscore header field ignoring, admin array index/path auth hardening
  • Built on Go 1.26.1+ — inherits Go runtime security patches

Recommendations

  • MERGE PRIORITY: HIGH — The old version (2.11.2) has 2 HIGH and 2 MEDIUM-severity vulnerabilities, all remediated in 2.11.4. No new vulnerabilities introduced.
  • Assessment: This patch-level update is small and safe — Caddy 2.11.4 is the latest 2.11.x release and fixes all known CVEs in the 2.11 series.
  • Action required: Merge this PR to close the security gap. No config changes needed.
  • MERGE ASAP — CVE-2026-45145 (FastCGI RCE) is the most concerning finding; if the deployment uses FastCGI (PHP), it is at risk.

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

@tinfoild
tinfoild Bot force-pushed the renovate/public.ecr.aws-docker-library-caddy-2.11.x branch 3 times, most recently from 670f186 to a09de9d Compare September 23, 2026 06:15
@tinfoild
tinfoild Bot force-pushed the renovate/public.ecr.aws-docker-library-caddy-2.11.x branch from a09de9d to 9f22ebb Compare October 2, 2026 23:08
@tinfoild tinfoild Bot changed the title fix(oci/library/caddy): update 2.11.2 ➼ 2.11.4 fix(oci/library/caddy): update 2.11.2 ➼ 2.11.6 Oct 2, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/public.ecr.aws-docker-library-caddy-2.11.x branch 2 times, most recently from 8d0a94c to e23ca6b Compare October 5, 2026 22:50
@tinfoild tinfoild Bot changed the title fix(oci/library/caddy): update 2.11.2 ➼ 2.11.6 fix(oci/library/caddy): update 2.11.2 ➼ 2.11.7 Oct 5, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/public.ecr.aws-docker-library-caddy-2.11.x branch from e23ca6b to b058f94 Compare October 6, 2026 10:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant