CVE-2026-27586
CriticalAdvisory
Published 24 Feb 2026In the index since 6 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.3
- base score, highest
- EPSS
- 0.003
- 19th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 23
- of 17,781 indexed, latest versions
- Container images
- 20
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Caddy: mTLS client authentication silently fails open when CA certificate file is missing or malformed
Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 20 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v2.2.0, v2.4.0, v2.4.2, v2.4.5+11 more | 2.11.1 | 20 |
- OSV records
- GHSA-hffm-g8v7-wrv7
- Also known as
- GO-2026-4539
Charts affected
23 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| baserowbaserow-chartVerified publisher | 1.0.56 | 1 of 6See more | 17,263 |
| caddy-ingress-controllercaddy-ingress | 1.3.0 | 1 of 1See more | 1,884 |
| convertigoconvertigoOfficialVerified publisher | 8.4.3 | 1 of 5See more | 17,404 |
| kubeviouskubevious | 1.2.2 | 1 of 7See more | 14,204 |
| maintenancecodewithemadVerified publisher | 0.1.6 | 1 of 1See more | 1,469 |
| gboxgboxVerified publisher | 1.0.5 | 1 of 2See more | 2,521 |
| headscale-uiheadscale-uiVerified publisher | 0.2.9 | 1 of 1See more | 1,476 |
| kubebrowsekubebrowse | 1.7.0 | 1 of 5See more | 4,141 |
| baserowblackbird-cloudVerified publisher | 1.0.17 | 1 of 6See more | 10,145 |
| parrot-mirroremmas-chartsVerified publisher | 1.0.0 | 1 of 1See more | 2,237 |
| supportpalevilgn0me | 0.1.6 | 1 of 1See more | 20,933 |
| searxgeek-cookbookVerified publisher | 5.6.2 | 1 of 4See more | 7,470 |
| vikunjageek-cookbookVerified publisher | 6.2.0 | 1 of 4See more | 6,893 |
| castopodhelmforgeVerified publisher | 1.2.7 | 1 of 3See more | 9,342 |
| discount-bandithelmforgeVerified publisher | 2.0.8 | 1 of 3See more | 29,817 |
| ryothelmforgeVerified publisher | 1.0.0 | 1 of 2See more | 6,012 |
| op-scim-bridgelifen | 1.0.3 | 1 of 2See more | 2,777 |
| op-scim-bridgelifen-chartsVerified publisher | 1.0.3 | 1 of 2See more | 2,777 |
| otlp-gatewayloafoe | 0.0.2 | 1 of 2See more | 2,155 |
| solgateloafoe | 0.0.12 | 1 of 1See more | 2,101 |
| gitlab-proxyopslevelVerified publisher | 0.0.8 | 1 of 1See more | 1,872 |
| caddysagikazarmarkVerified publisher | 0.0.14 | 1 of 1See more | 2,960 |
| tfy-cloudflaredtruefoundryVerified publisher | 0.5.0 | 1 of 2See more | 2,015 |
Container images carrying it
20 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| caddy/ | 18d1366fc0e9 | github.com/ | 2.11.1 | 3 |
| 1password/ | 29d0c6cb67eb | github.com/ | 2.11.1 | 2 |
| baserow/ | df0c42eb67e8 | github.com/ | 2.11.1 | 1 |
| castopod/ | 4e4f0440520f | github.com/ | 2.11.1 | 1 |
| cybrarist/ | e9e2447ac666 | github.com/ | 2.11.1 | 1 |
| gboxproxy/ | 3a9f4a711d5c | github.com/ | 2.11.1 | 1 |
| kubevious/ | 6233e84bdd59 | github.com/ | 2.11.1 | 1 |
| library/ | 60fb54d36b4b | github.com/ | 2.11.1 | 1 |
| library/ | 7367adca165f | github.com/ | 2.11.1 | 1 |
| library/ | 874405536b3e | github.com/ | 2.11.1 | 1 |
| library/ | b4e3952384eb | github.com/ | 2.11.1 | 1 |
| library/ | fbc51bcf1ab0 | github.com/ | 2.11.1 | 1 |
| ghcr.io/ | bd6bea5e487c | github.com/ | 2.11.1 | 1 |
| ghcr.io/ | 015f5ba04bcb | github.com/ | 2.11.1 | 1 |
| ghcr.io/ | a752b6aee537 | github.com/ | 2.11.1 | 1 |
| ghcr.io/ | 528f2174fa2f | github.com/ | 2.11.1 | 1 |
| ghcr.io/ | b3256cbc7b68 | github.com/ | 2.11.1 | 1 |
| public.ecr.aws/ | 87cbd356af2e | github.com/ | 2.11.1 | 1 |
| public.ecr.aws/ | 573779e57fae | github.com/ | 2.11.1 | 1 |
| registry.gitlab.com/ | f91b602ca572 | github.com/ | 2.11.1 | 1 |