JasonLovesDoggo Caddy Defender
- < 0.10.1
A vulnerability in the Caddy Defender plugin prior to version 0.10.1 allows requests from blocked IP ranges to bypass defense mechanisms when Caddy is behind a trusted proxy, CDN, or load balancer. The issue arises because Defender relied on 'r.RemoteAddr', which only reflects the immediate connection peer—typically the proxy—rather than the original client. Although Caddy can resolve the true client IP after applying the 'trusted_proxies' policy, Defender did not utilize this information. Consequently, in affected deployments, clients could circumvent IP blocking by accessing Caddy through an unblocked proxy.
Exploitation of this vulnerability allows clients from blocked IP ranges to bypass Caddy Defender's request blocking, potentially leading to undesired access or actions on the server.
Users should upgrade to Caddy Defender version 0.10.1 or later. For those unable to upgrade immediately, it is recommended to enforce equivalent IP blocking at the trusted proxy, CDN, load balancer, firewall, or other edge layer before traffic reaches Caddy.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.