{"id":"CVE-2026-92284","published":"2026-09-23T19:19:43.940","lastModified":"2026-09-23T20:17:21.903","description":"Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/replacer.go, resolving http.request.body reads the complete request body with an unbounded io.Copy before request-body middleware limits apply, allowing memory exhaustion and process termination.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-770"],"vendors":[],"products":[],"references":[{"url":"https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9","tags":[]},{"url":"https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9","tags":[]}],"exploitRefs":[{"url":"https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9","tags":[]},{"url":"https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9","tags":[]}],"hasPoc":true,"ai":null}