CVE-2026-27585
HighAdvisory
Published 24 Feb 2026In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.2
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 23
- of 17,781 indexed, latest versions
- Container images
- 20
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Caddy: Improper sanitization of glob characters in file matcher may lead to bypassing security protections
Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 20 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v2.2.0, v2.4.0, v2.4.2, v2.4.5+11 more | 2.11.1 | 20 |
- OSV records
- GHSA-4xrr-hq4w-6vf4
- Also known as
- GO-2026-4535
Charts affected
23 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| baserowbaserow-chartVerified publisher | 1.0.56 | 1 of 6See more | 17,263 |
| caddy-ingress-controllercaddy-ingress | 1.3.0 | 1 of 1See more | 1,884 |
| convertigoconvertigoOfficialVerified publisher | 8.4.3 | 1 of 5See more | 17,404 |
| kubeviouskubevious | 1.2.2 | 1 of 7See more | 14,204 |
| maintenancecodewithemadVerified publisher | 0.1.6 | 1 of 1See more | 1,469 |
| gboxgboxVerified publisher | 1.0.5 | 1 of 2See more | 2,521 |
| headscale-uiheadscale-uiVerified publisher | 0.2.9 | 1 of 1See more | 1,476 |
| kubebrowsekubebrowse | 1.7.0 | 1 of 5See more | 4,141 |
| baserowblackbird-cloudVerified publisher | 1.0.17 | 1 of 6See more | 10,145 |
| parrot-mirroremmas-chartsVerified publisher | 1.0.0 | 1 of 1See more | 2,237 |
| supportpalevilgn0me | 0.1.6 | 1 of 1See more | 20,933 |
| searxgeek-cookbookVerified publisher | 5.6.2 | 1 of 4See more | 7,470 |
| vikunjageek-cookbookVerified publisher | 6.2.0 | 1 of 4See more | 6,893 |
| castopodhelmforgeVerified publisher | 1.2.7 | 1 of 3See more | 9,342 |
| discount-bandithelmforgeVerified publisher | 2.0.8 | 1 of 3See more | 29,817 |
| ryothelmforgeVerified publisher | 1.0.0 | 1 of 2See more | 6,012 |
| op-scim-bridgelifen | 1.0.3 | 1 of 2See more | 2,777 |
| op-scim-bridgelifen-chartsVerified publisher | 1.0.3 | 1 of 2See more | 2,777 |
| otlp-gatewayloafoe | 0.0.2 | 1 of 2See more | 2,155 |
| solgateloafoe | 0.0.12 | 1 of 1See more | 2,101 |
| gitlab-proxyopslevelVerified publisher | 0.0.8 | 1 of 1See more | 1,872 |
| caddysagikazarmarkVerified publisher | 0.0.14 | 1 of 1See more | 2,960 |
| tfy-cloudflaredtruefoundryVerified publisher | 0.5.0 | 1 of 2See more | 2,015 |
Container images carrying it
20 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| caddy/ | 18d1366fc0e9 | github.com/ | 2.11.1 | 3 |
| 1password/ | 29d0c6cb67eb | github.com/ | 2.11.1 | 2 |
| baserow/ | df0c42eb67e8 | github.com/ | 2.11.1 | 1 |
| castopod/ | 4e4f0440520f | github.com/ | 2.11.1 | 1 |
| cybrarist/ | e9e2447ac666 | github.com/ | 2.11.1 | 1 |
| gboxproxy/ | 3a9f4a711d5c | github.com/ | 2.11.1 | 1 |
| kubevious/ | 6233e84bdd59 | github.com/ | 2.11.1 | 1 |
| library/ | 60fb54d36b4b | github.com/ | 2.11.1 | 1 |
| library/ | 7367adca165f | github.com/ | 2.11.1 | 1 |
| library/ | 874405536b3e | github.com/ | 2.11.1 | 1 |
| library/ | b4e3952384eb | github.com/ | 2.11.1 | 1 |
| library/ | fbc51bcf1ab0 | github.com/ | 2.11.1 | 1 |
| ghcr.io/ | bd6bea5e487c | github.com/ | 2.11.1 | 1 |
| ghcr.io/ | 015f5ba04bcb | github.com/ | 2.11.1 | 1 |
| ghcr.io/ | a752b6aee537 | github.com/ | 2.11.1 | 1 |
| ghcr.io/ | 528f2174fa2f | github.com/ | 2.11.1 | 1 |
| ghcr.io/ | b3256cbc7b68 | github.com/ | 2.11.1 | 1 |
| public.ecr.aws/ | 87cbd356af2e | github.com/ | 2.11.1 | 1 |
| public.ecr.aws/ | 573779e57fae | github.com/ | 2.11.1 | 1 |
| registry.gitlab.com/ | f91b602ca572 | github.com/ | 2.11.1 | 1 |