Caddy Open Redirect Vulnerability

Vulnerability

An open redirect vulnerability has been identified in Caddy version 2.4. A remote, unauthenticated attacker can exploit this issue to redirect users to arbitrary web URLs by crafting deceptive links that trick victims into clicking them.

Impact

Exploitation of this vulnerability could lead to open redirect, allowing attackers to manipulate user navigation to potentially malicious sites.

Remediation

Users can upgrade to Caddy version 2.4.6 to address this vulnerability. Instructions for updating Caddy on Fedora are available in the Fedora Update Notification.

Added: Jun 22, 2026, 10:56 AM
Updated: Jun 22, 2026, 10:56 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.2
exploitability
7.0
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.