StackRadar

CVE-2026-30852

Unscored

Advisory

Published 10 Mar 2026In the index since 6 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Caddy's vars_regexp double-expands user input, leaking env vars and files in github.com/caddyserver/caddy

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
github.com/caddyserver/caddy/v2golangv2.7.5, v2.7.6, v2.8.4, v2.9.1+1 more2.11.29
OSV records
GO-2026-4644
Also known as
GHSA-m2w3-8f23-hxxf

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
baserowbaserow-chartVerified publisher1.0.561 of 6See more

baserow baserow-chart 1.0.56

1 of the 6 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
github.com/caddyserver/caddy/v2@v2.7.5
2.11.2

Open the chart page →

17,263
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
github.com/caddyserver/caddy/v2@v2.7.5
2.11.2

Open the chart page →

1,884
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
github.com/caddyserver/caddy/v2@v2.7.6
2.11.2

Open the chart page →

17,404
maintenancecodewithemadVerified publisher0.1.61 of 1See more

maintenance codewithemad 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
library/caddy:2.9-alpineb4e3952384eb
github.com/caddyserver/caddy/v2@v2.9.1
2.11.2

Open the chart page →

1,469
headscale-uiheadscale-uiVerified publisher0.2.91 of 1See more

headscale-ui headscale-ui 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
github.com/caddyserver/caddy/v2@v2.10.2
2.11.2

Open the chart page →

1,476
kubebrowsekubebrowse1.7.01 of 5See more

kubebrowse kubebrowse 1.7.0

1 of the 5 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
github.com/caddyserver/caddy/v2@v2.10.2
2.11.2

Open the chart page →

4,141
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
github.com/caddyserver/caddy/v2@v2.7.5
2.11.2

Open the chart page →

10,145
castopodhelmforgeVerified publisher1.2.71 of 3See more

castopod helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
github.com/caddyserver/caddy/v2@v2.10.2
2.11.2

Open the chart page →

9,342
discount-bandithelmforgeVerified publisher2.0.81 of 3See more

discount-bandit helmforge 2.0.8

1 of the 3 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
cybrarist/discount-bandit:v4.0.4e9e2447ac666
github.com/caddyserver/caddy/v2@v2.10.2
2.11.2

Open the chart page →

29,817
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
github.com/caddyserver/caddy/v2@v2.9.1
2.11.2

Open the chart page →

6,012
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-30852.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
github.com/caddyserver/caddy/v2@v2.8.4
2.11.2

Open the chart page →

2,155

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
caddy/ingress:v0.2.118d1366fc0e9
github.com/caddyserver/caddy/v2@v2.7.5
2.11.2
3
baserow/baserow:1.30.1df0c42eb67e8
github.com/caddyserver/caddy/v2@v2.7.6
2.11.2
1
castopod/castopod:1.15.54e4f0440520f
github.com/caddyserver/caddy/v2@v2.10.2
2.11.2
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
github.com/caddyserver/caddy/v2@v2.10.2
2.11.2
1
library/caddy:2.9-alpineb4e3952384eb
github.com/caddyserver/caddy/v2@v2.9.1
2.11.2
1
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
github.com/caddyserver/caddy/v2@v2.10.2
2.11.2
1
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
github.com/caddyserver/caddy/v2@v2.10.2
2.11.2
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
github.com/caddyserver/caddy/v2@v2.9.1
2.11.2
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
github.com/caddyserver/caddy/v2@v2.8.4
2.11.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.