CVE-2026-52846
Last modified
CVE-2026-52846 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely. This vulnerability is fixed in 2.11.4.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Caddyserver | Caddy | < 2.11.4 |
References
- https://github.com/caddyserver/caddy/security/advisories/GHSA-vcc4-2c75-vc9vExploit, Third Party Advisory
- https://github.com/caddyserver/caddy/security/advisories/GHSA-vcc4-2c75-vc9vExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-52846?
How severe is CVE-2026-52846?
How do I fix CVE-2026-52846?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-52840Easy!Appointments is a self hosted appointment scheduler. In…2.7
- CVE-2026-52841Easy!Appointments is a self hosted appointment scheduler. In…3.1
- CVE-2026-52842Lightpanda is a headless browser designed for AI and automat…9.3
- CVE-2026-52843Lightpanda is a headless browser designed for AI and automat…9.3
- CVE-2026-52844Caddy is an extensible server platform that uses TLS by defa…7.5
- CVE-2026-52845Caddy is an extensible server platform that uses TLS by defa…8.1
- CVE-2026-5285Use after free in WebGL in Google Chrome prior to 146.0.7680…8.8
- CVE-2026-52855Wings is the server control plane for Pterodactyl, a free, o…9.9
- CVE-2026-52856Wings is the server control plane for Pterodactyl, a free, o…7.5
- CVE-2026-52857Wings is the server control plane for Pterodactyl, a free, o…5.5
- CVE-2026-52858Vim is an open source, command line text editor. Prior to ve…7.8
- CVE-2026-52859Vim is an open source, command line text editor. Prior to ve…8.2
Are you affected by CVE-2026-52846?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
