fix(deps): update module github.com/caddyserver/caddy/v2 to v2.11.7 #14

Open
renovate wants to merge 1 commit from renovate/all-patch into main
Collaborator

This PR contains the following updates:

Package Change Age Confidence
github.com/caddyserver/caddy/v2 v2.11.4 → v2.11.7 age confidence

Release Notes

caddyserver/caddy (github.com/caddyserver/caddy/v2)

v2.11.7

Compare Source

This patch release fixes regressions from 2.11.6, including a crash when proxying over HTTP/2 and streams that were cut off after a minute. If you're on 2.11.6, we recommend upgrading. It also adds support for the brand new Incremental header field (RFC 10036).

Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.

Highlights
  • Fixed: crash and dropped streams caused by the new idle timeouts. 2.11.6 introduced default idle read/write timeouts, which caused some problems:

    • In 2.11.6, the request body's idle deadline could outlive the handler that set it:

      • Over HTTP/2, Caddy could panic with a nil pointer dereference when the reverse proxy was still reading a request body after the handler had returned. (#​8101)
      • Over HTTP/1.1, streaming responses to requests with a body, such as SSE clients that open the stream with a POST, were cut off exactly 60 seconds after the body was read. (#​8103)

      Both are fixed in #​8107. Thanks @​steadytao!

    • Over HTTP/2, streaming responses that paused between writes for longer than write_idle (1 minute by default), like quiet SSE streams, were reset with a stream error. As documented, only a write that stalls should count. Thanks @​WeidiDeng! (#​8118, #​8119)

  • Fixed: placeholders for missing cookies are empty again. Since 2.11.6, places that keep unknown placeholders as written, like respond headers, would output {http.request.cookie.*} literally when the cookie wasn't in the request. The same happened to {http.request.tls.*} on plain HTTP requests. Both are empty again. Thanks @​steadytao! (#​8019)

  • New: support for the Incremental header field (RFC 10036). It's the standard replacement for NGINX's proprietary X-Accel-Buffering header. If an upstream response has Incremental: ?1, reverse_proxy forwards it immediately, the same as flush_interval -1, and encode streams it instead of holding it back. Great for Mercure, SSE and other streaming apps.

    • If the request_buffers or response_buffers options would prevent incremental forwarding, Caddy responds with 501 Not Implemented instead of silently buffering, as the RFC requires.
    • The new proxy_status_name option adds a Proxy-Status header to those responses, explaining why the message was refused.

    Thanks @​dunglas! (#​8020)

  • Faster TLS handshakes: When nothing subscribes to certificate events and debug logging is off, CertMagic no longer builds event data for every handshake. Certificate lookup per handshake is about twice as fast, with 10 allocations instead of 15. Thanks @​u5surf! (#​8010)

  • Unix sockets: When a reload moves a listener (or the admin endpoint) off a Unix socket, the old socket now closes right away and its file is removed. Before, clients connecting to the old path would hang until the next garbage collection, about 2 minutes later. Thanks @​littfed! (#​8061)

  • Headers handler: Multiple Set-Cookie values in a JSON config's set are now sent as separate header fields, instead of being joined with commas into one field that clients can't parse. Thanks @​Indra55! (#​8080)

  • caddy fmt no longer deletes an opening brace at the very end of the input. Thanks @​n0liu! (#​8047)

What's Changed
New Contributors

Full Changelog: https://github.com/caddyserver/caddy/compare/v2.11.6...v2.11.7

v2.11.6

Compare Source

This patch release contains a large number of minor and some noticeable enhancements and bug fixes. Thank you to everyone who contributed or spent their LLM tokens responsibly to help with this release!

We have much more in the pipeline still, as AI has made contributions of all quality levels cheap and easy. We will be trying to go through them as quickly and efficiently as we can.

Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.

⚠️ Please read the breaking changes below before upgrading. Most of them come from security hardening, and most configs won't notice. If you were relying on one of the old behaviors, though, you'll want to know about it.

Highlights
  • New url_pattern request matcher: Match requests with the URLPattern standard, the same syntax used by browsers (JS) and many web frameworks. It supports named groups, wildcards, and regexp components. Captured groups become placeholders ({http.url_pattern.<component>.<group>}), and there's a matching url_pattern CEL function too. Thanks @​dunglas! (#​7787)
  • Slowloris mitigation: New idle read/write timeouts reset on every successful read or write. A stalled connection gets cut off, and a slow one that's still making progress is left alone. You can also set optional minimum transfer rates, and there's a new timeouts handler directive for per-route tuning. (#​7913)
  • New tls_automate_names global option: Manage certificates for names without serving them in a site block. (#​8015)
  • New expected_underscore_headers server option: If dropping header fields with underscores in 2.11.4 broke your app, you can now list the specific headers to keep. (#​7809)
  • HTTP/3 over Tailscale and other low-MTU links now works, because the initial QUIC packet size is smaller. (#​7886)
  • Reverse proxy got more love:
    • partial responses are flushed to clients properly (#​7849)
    • TCP half-close is propagated on upgraded streams (#​8027)
    • versions 3 upstreams now honor tls_trust_pool (#​8042)
    • active health check state is kept separate per check config, so one handler's failing probes don't mark the upstream down for everyone else (#​7916)
    • the random_choose policy distributes correctly now (#​7873)
  • Server-sent events behind encode now stream immediately instead of being buffered. (#​7905)
  • Graceful shutdown now waits for servers left over from previous configs, so long-lived responses that started before a reload aren't cut off at exit. (#​8009)
  • Caddyfile: import now works inside named routes (#​7986), and quoted braces are treated as literal arguments (#​7875).
  • Logging:
  • Performance: fewer allocations in request hot paths, encoding negotiation, and the reverse proxy, from @​jvoisin and @​dunglas. Directory browsing is much faster for large directories. (#​7847, #​7903, #​7911, #​7925, #​7926, #​7936)
  • Other new stuff:
    • {http.request.proto_name} placeholder (#​7782)
    • FastCGI populates SERVER_ADDR (#​7912)
    • multiple authentication providers no longer clobber each other's responses (#​7904)
⚠️ Breaking changes
  • Go 1.26 is now the minimum version for building Caddy and plugins. (#​8056)
  • Request headers are limited to 16 KiB by default. Before, we used Go's 1 MB default. Requests with larger headers (giant cookies, oversized tokens, etc.) will now get 431 Request Header Fields Too Large. If you need more, raise it with the max_header_size server option.
  • New 1-minute idle read/write timeouts by default. If a request body read or a response write stalls (makes no progress at all) for longer than that, the connection is aborted. Pauses between writes, like with SSE, don't count. Some long-lived streams where the client goes quiet mid-body may be affected. You can tune these with read_body_idle and write_idle in the timeouts server option, or per-route with the timeouts directive. (#​7913)
  • Request header fields containing . are now dropped, the same way underscores were in 2.11.4. PHP folds . to _, so these could be used to impersonate legitimate headers. If you need specific ones, allow them with the new expected_dot_headers server option.
  • A wildcard site's client_auth no longer applies to more specific hostnames that have their own site blocks. For example, public.example.com no longer inherits mTLS from *.example.com. If you were counting on that inheritance, configure client_auth on the specific site explicitly. (#​7920)
  • Stricter config validation. Some configs that used to be silently accepted (and probably didn't do what you expected) are now errors:
    • duplicate named_routes (#​7800)
    • duplicate forward_auth uri (#​7814)
    • invalid weighted_round_robin weights (#​7807)
    • a non-integer browse file_limit (#​7988)
    • duplicate or ambiguous map inputs (#​8067)
    • malformed map destination placeholders (#​8074)
    • module paths with ambiguous @ version separators (#​7974)
  • Admin API /load now returns 400 with warnings inside a valid JSON body when a config is invalid. Before, it returned 200 with two concatenated JSON objects. (#​7267)
  • method matcher values are normalized to uppercase, so method get now matches GET requests. (#​7832)
Security fixes

Thank you to everyone who reported responsibly and helped with patches:

  • reverseproxy: When a route used both forward_auth and reverse_proxy, a request could be sent on the wrong upstream connection. Reported by @​carlt, fixed by @​WeidiDeng. (GHSA-6365-7ppr-5r92, #​7859)
  • reverseproxy: Hop-by-hop headers from upstreams are now stripped from 101 Switching Protocols responses too. Thanks @​jirn073-76.
  • caddyhttp: handle_path and uri strip_prefix/strip_suffix now canonicalize the resulting path, so it can't bypass path-based authorization. Thanks @​steadytao.
  • caddyhttp: Extended the 2.11.4 header-alias filter to . (see above) to prevent bypassing forward_auth copy_headers with PHP/FastCGI backends. Thanks @​dunglas.
  • caddyhttp: The path_regexp matcher now normalizes Windows backslashes like the path matcher does. This completes the fix for CVE-2026-52844. Thanks @​thientd. (#​7858)
  • fileserver: Windows 8.3 short names are rejected in every path component, not just the last one. Thanks @​DavidCarliez. (#​7952)
  • fileserver: Fixed ETag collisions between files with different modification times and sizes. Thanks @​dunglas.
  • fastcgi: The client's Proxy header is no longer passed to backends as HTTP_PROXY (HTTPoxy). Thanks @​bzyy1024. (#​7934)
  • reverseproxy: Sticky session cookie hashes are compared in constant time. Thanks @​alhudz. (#​7853)
  • admin: Request paths are normalized in the remote admin access check, and origin/host allow-lists compare case-insensitively (defense-in-depth). Thanks @​AmariahAK, @​mohammed90, and @​hktitof. (#​7910, #​7973, #​7993)
  • caddyhttp: Oversized request bodies used through placeholders now correctly return 413. Thanks @​hktitof. (#​7969)

⚠️ These security patches may be breaking if your application relies on the buggy behaviors.

🚨 Notice for Caddy plugin maintainers: Dependabot will probably alert you to the security fixes in Caddy and urge you to upgrade it in your go.mod file. Please ONLY upgrade the Caddy dependency if there's a change to an exported API your plugin uses. Note that doing so now also requires Go 1.26.

Thank you to everyone who was involved this release, especially our 40 new contributors! 🎉

What's Changed
New Contributors

Full Changelog: https://github.com/caddyserver/caddy/compare/v2.11.4...v2.11.6

v2.11.5

Compare Source


Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [github.com/caddyserver/caddy/v2](https://github.com/caddyserver/caddy) | `v2.11.4` → `v2.11.7` | ![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fcaddyserver%2fcaddy%2fv2/v2.11.7?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fcaddyserver%2fcaddy%2fv2/v2.11.4/v2.11.7?slim=true) | --- ### Release Notes <details> <summary>caddyserver/caddy (github.com/caddyserver/caddy/v2)</summary> ### [`v2.11.7`](https://github.com/caddyserver/caddy/releases/tag/v2.11.7) [Compare Source](https://github.com/caddyserver/caddy/compare/v2.11.6...v2.11.7) This patch release fixes regressions from 2.11.6, including a crash when proxying over HTTP/2 and streams that were cut off after a minute. **If you're on 2.11.6, we recommend upgrading.** It also adds support for the brand new `Incremental` header field (RFC 10036). **Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.** ##### Highlights - **Fixed: crash and dropped streams caused by the new idle timeouts.** 2.11.6 introduced default idle read/write timeouts, which caused some problems: - In 2.11.6, the request body's idle deadline could outlive the handler that set it: - Over HTTP/2, Caddy could panic with a nil pointer dereference when the reverse proxy was still reading a request body after the handler had returned. ([#&#8203;8101](https://github.com/caddyserver/caddy/issues/8101)) - Over HTTP/1.1, streaming responses to requests with a body, such as SSE clients that open the stream with a `POST`, were cut off exactly 60 seconds after the body was read. ([#&#8203;8103](https://github.com/caddyserver/caddy/issues/8103)) Both are fixed in [#&#8203;8107](https://github.com/caddyserver/caddy/issues/8107). Thanks [@&#8203;steadytao](https://github.com/steadytao)! - Over HTTP/2, streaming responses that paused between writes for longer than [`write_idle`](https://caddyserver.com/docs/caddyfile/options#timeouts) (1 minute by default), like quiet SSE streams, were reset with a stream error. As documented, only a write that stalls should count. Thanks [@&#8203;WeidiDeng](https://github.com/WeidiDeng)! ([#&#8203;8118](https://github.com/caddyserver/caddy/issues/8118), [#&#8203;8119](https://github.com/caddyserver/caddy/issues/8119)) - **Fixed: placeholders for missing cookies are empty again.** Since 2.11.6, places that keep unknown placeholders as written, like [`respond`](https://caddyserver.com/docs/caddyfile/directives/respond) headers, would output `{http.request.cookie.*}` literally when the cookie wasn't in the request. The same happened to `{http.request.tls.*}` on plain HTTP requests. Both are empty again. Thanks [@&#8203;steadytao](https://github.com/steadytao)! ([#&#8203;8019](https://github.com/caddyserver/caddy/issues/8019)) - **New: support for the [`Incremental`](https://www.rfc-editor.org/rfc/rfc10036.html) header field (RFC 10036).** It's the standard replacement for NGINX's proprietary `X-Accel-Buffering` header. If an upstream response has `Incremental: ?1`, [`reverse_proxy`](https://caddyserver.com/docs/caddyfile/directives/reverse_proxy#streaming) forwards it immediately, the same as [`flush_interval -1`](https://caddyserver.com/docs/caddyfile/directives/reverse_proxy#flush_interval), and [`encode`](https://caddyserver.com/docs/caddyfile/directives/encode) streams it instead of holding it back. Great for [Mercure](https://mercure.rocks), SSE and other streaming apps. - If the [`request_buffers`](https://caddyserver.com/docs/caddyfile/directives/reverse_proxy#request_buffers) or [`response_buffers`](https://caddyserver.com/docs/caddyfile/directives/reverse_proxy#response_buffers) options would prevent incremental forwarding, Caddy responds with `501 Not Implemented` instead of silently buffering, as the RFC requires. - The new [`proxy_status_name`](https://caddyserver.com/docs/caddyfile/directives/reverse_proxy#proxy_status_name) option adds a `Proxy-Status` header to those responses, explaining why the message was refused. Thanks [@&#8203;dunglas](https://github.com/dunglas)! ([#&#8203;8020](https://github.com/caddyserver/caddy/issues/8020)) - **Faster TLS handshakes:** When nothing subscribes to certificate events and debug logging is off, CertMagic no longer builds event data for every handshake. Certificate lookup per handshake is about twice as fast, with 10 allocations instead of 15. Thanks [@&#8203;u5surf](https://github.com/u5surf)! ([#&#8203;8010](https://github.com/caddyserver/caddy/issues/8010)) - **Unix sockets:** When a reload moves a listener (or the admin endpoint) off a Unix socket, the old socket now closes right away and its file is removed. Before, clients connecting to the old path would hang until the next garbage collection, about 2 minutes later. Thanks [@&#8203;littfed](https://github.com/littfed)! ([#&#8203;8061](https://github.com/caddyserver/caddy/issues/8061)) - **Headers handler:** Multiple `Set-Cookie` values in a JSON config's `set` are now sent as separate header fields, instead of being joined with commas into one field that clients can't parse. Thanks [@&#8203;Indra55](https://github.com/Indra55)! ([#&#8203;8080](https://github.com/caddyserver/caddy/issues/8080)) - **`caddy fmt`** no longer deletes an opening brace at the very end of the input. Thanks [@&#8203;n0liu](https://github.com/n0liu)! ([#&#8203;8047](https://github.com/caddyserver/caddy/issues/8047)) ##### What's Changed - events: tell CertMagic which events are worth emitting by [@&#8203;u5surf](https://github.com/u5surf) in [#&#8203;8010](https://github.com/caddyserver/caddy/pull/8010) - feat: implement the Incremental header field (RFC 10036) by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;8020](https://github.com/caddyserver/caddy/pull/8020) - caddyfile: Keep an opening brace that ends the input by [@&#8203;n0liu](https://github.com/n0liu) in [#&#8203;8047](https://github.com/caddyserver/caddy/pull/8047) - listeners: close unix socket immediately and unlink file on reload by [@&#8203;littfed](https://github.com/littfed) in [#&#8203;8061](https://github.com/caddyserver/caddy/pull/8061) - reverseproxy: stabilise half-close test by [@&#8203;steadytao](https://github.com/steadytao) in [#&#8203;8049](https://github.com/caddyserver/caddy/pull/8049) - caddyhttp: keep absent optional placeholders empty by [@&#8203;steadytao](https://github.com/steadytao) in [#&#8203;8019](https://github.com/caddyserver/caddy/pull/8019) - headers: Preserve separate Set-Cookie values by [@&#8203;Indra55](https://github.com/Indra55) in [#&#8203;8080](https://github.com/caddyserver/caddy/pull/8080) - caddyhttp: end request-body deadline ownership with handler by [@&#8203;steadytao](https://github.com/steadytao) in [#&#8203;8107](https://github.com/caddyserver/caddy/pull/8107) - timeouts: fix idle writer terminate h2 response writers between writes by [@&#8203;WeidiDeng](https://github.com/WeidiDeng) in [#&#8203;8119](https://github.com/caddyserver/caddy/pull/8119) ##### New Contributors - [@&#8203;n0liu](https://github.com/n0liu) made their first contribution in [#&#8203;8047](https://github.com/caddyserver/caddy/pull/8047) - [@&#8203;littfed](https://github.com/littfed) made their first contribution in [#&#8203;8061](https://github.com/caddyserver/caddy/pull/8061) **Full Changelog**: <https://github.com/caddyserver/caddy/compare/v2.11.6...v2.11.7> ### [`v2.11.6`](https://github.com/caddyserver/caddy/releases/tag/v2.11.6) [Compare Source](https://github.com/caddyserver/caddy/compare/v2.11.5...v2.11.6) This patch release contains a large number of minor and some noticeable enhancements and bug fixes. Thank you to everyone who contributed or spent their LLM tokens responsibly to help with this release! We have much more in the pipeline still, as AI has made contributions of all quality levels cheap and easy. We will be trying to go through them as quickly and efficiently as we can. **Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.** :warning: **Please read the breaking changes below before upgrading.** Most of them come from security hardening, and most configs won't notice. If you were relying on one of the old behaviors, though, you'll want to know about it. ##### Highlights - **New [`url_pattern` request matcher](https://caddyserver.com/docs/caddyfile/matchers#url-pattern):** Match requests with the [URLPattern](https://urlpattern.spec.whatwg.org/) standard, the same syntax used by browsers (JS) and many web frameworks. It supports named groups, wildcards, and regexp components. Captured groups become placeholders (`{http.url_pattern.<component>.<group>}`), and there's a matching `url_pattern` CEL function too. Thanks [@&#8203;dunglas](https://github.com/dunglas)! ([#&#8203;7787](https://github.com/caddyserver/caddy/issues/7787)) - **Slowloris mitigation:** New idle read/write timeouts reset on every successful read or write. A stalled connection gets cut off, and a slow one that's still making progress is left alone. You can also set optional minimum transfer rates, and there's a new [`timeouts`](https://caddyserver.com/docs/caddyfile/directives/timeouts) handler directive for per-route tuning. ([#&#8203;7913](https://github.com/caddyserver/caddy/issues/7913)) - **New [`tls_automate_names`](https://caddyserver.com/docs/caddyfile/options#tls-automate-names) global option:** Manage certificates for names without serving them in a site block. ([#&#8203;8015](https://github.com/caddyserver/caddy/issues/8015)) - **New [`expected_underscore_headers`](https://caddyserver.com/docs/caddyfile/options#expected-underscore-headers) server option:** If dropping header fields with underscores in 2.11.4 broke your app, you can now list the specific headers to keep. ([#&#8203;7809](https://github.com/caddyserver/caddy/issues/7809)) - **HTTP/3 over Tailscale and other low-MTU links** now works, because the initial QUIC packet size is smaller. ([#&#8203;7886](https://github.com/caddyserver/caddy/issues/7886)) - **Reverse proxy got more love:** - partial responses are flushed to clients properly ([#&#8203;7849](https://github.com/caddyserver/caddy/issues/7849)) - TCP half-close is propagated on upgraded streams ([#&#8203;8027](https://github.com/caddyserver/caddy/issues/8027)) - `versions 3` upstreams now honor [`tls_trust_pool`](https://caddyserver.com/docs/caddyfile/directives/reverse_proxy#tls_trust_pool) ([#&#8203;8042](https://github.com/caddyserver/caddy/issues/8042)) - [active health check](https://caddyserver.com/docs/caddyfile/directives/reverse_proxy#active-health-checks) state is kept separate per check config, so one handler's failing probes don't mark the upstream down for everyone else ([#&#8203;7916](https://github.com/caddyserver/caddy/issues/7916)) - the `random_choose` policy distributes correctly now ([#&#8203;7873](https://github.com/caddyserver/caddy/issues/7873)) - **Server-sent events behind [`encode`](https://caddyserver.com/docs/caddyfile/directives/encode)** now stream immediately instead of being buffered. ([#&#8203;7905](https://github.com/caddyserver/caddy/issues/7905)) - **Graceful shutdown** now waits for servers left over from previous configs, so long-lived responses that started before a reload aren't cut off at exit. ([#&#8203;8009](https://github.com/caddyserver/caddy/issues/8009)) - **Caddyfile:** [`import`](https://caddyserver.com/docs/caddyfile/directives/import) now works inside [named routes](https://caddyserver.com/docs/caddyfile/concepts#named-routes) ([#&#8203;7986](https://github.com/caddyserver/caddy/issues/7986)), and quoted braces are treated as literal arguments ([#&#8203;7875](https://github.com/caddyserver/caddy/issues/7875)). - **Logging:** - new [`set_cookie`](https://caddyserver.com/docs/caddyfile/directives/log#set-cookie) log filter ([#&#8203;7888](https://github.com/caddyserver/caddy/issues/7888)) - [`roll_interval`](https://caddyserver.com/docs/caddyfile/directives/log#roll_interval) accepts days (`d`) ([#&#8203;7900](https://github.com/caddyserver/caddy/issues/7900)) - recovered handler panics are logged at ERROR level ([#&#8203;7924](https://github.com/caddyserver/caddy/issues/7924)) - write timeout errors show up in access logs ([#&#8203;7945](https://github.com/caddyserver/caddy/issues/7945)) - **Performance:** fewer allocations in request hot paths, encoding negotiation, and the reverse proxy, from [@&#8203;jvoisin](https://github.com/jvoisin) and [@&#8203;dunglas](https://github.com/dunglas). Directory browsing is much faster for large directories. ([#&#8203;7847](https://github.com/caddyserver/caddy/issues/7847), [#&#8203;7903](https://github.com/caddyserver/caddy/issues/7903), [#&#8203;7911](https://github.com/caddyserver/caddy/issues/7911), [#&#8203;7925](https://github.com/caddyserver/caddy/issues/7925), [#&#8203;7926](https://github.com/caddyserver/caddy/issues/7926), [#&#8203;7936](https://github.com/caddyserver/caddy/issues/7936)) - **Other new stuff:** - `{http.request.proto_name}` placeholder ([#&#8203;7782](https://github.com/caddyserver/caddy/issues/7782)) - FastCGI populates `SERVER_ADDR` ([#&#8203;7912](https://github.com/caddyserver/caddy/issues/7912)) - multiple `authentication` providers no longer clobber each other's responses ([#&#8203;7904](https://github.com/caddyserver/caddy/issues/7904)) ##### :warning: Breaking changes - **Go 1.26 is now the minimum version** for building Caddy and plugins. ([#&#8203;8056](https://github.com/caddyserver/caddy/issues/8056)) - **Request headers are limited to 16 KiB by default.** Before, we used Go's 1 MB default. Requests with larger headers (giant cookies, oversized tokens, etc.) will now get `431 Request Header Fields Too Large`. If you need more, raise it with the [`max_header_size`](https://caddyserver.com/docs/caddyfile/options#max-header-size) server option. - **New 1-minute idle read/write timeouts by default.** If a request body read or a response write stalls (makes no progress at all) for longer than that, the connection is aborted. Pauses *between* writes, like with SSE, don't count. Some long-lived streams where the client goes quiet mid-body may be affected. You can tune these with `read_body_idle` and `write_idle` in the [`timeouts`](https://caddyserver.com/docs/caddyfile/options#timeouts) server option, or per-route with the [`timeouts`](https://caddyserver.com/docs/caddyfile/directives/timeouts) directive. ([#&#8203;7913](https://github.com/caddyserver/caddy/issues/7913)) - **Request header fields containing `.` are now dropped**, the same way underscores were in 2.11.4. PHP folds `.` to `_`, so these could be used to impersonate legitimate headers. If you need specific ones, allow them with the new [`expected_dot_headers`](https://caddyserver.com/docs/caddyfile/options#expected-dot-headers) server option. - **A wildcard site's [`client_auth`](https://caddyserver.com/docs/caddyfile/directives/tls#client_auth) no longer applies to more specific hostnames that have their own site blocks.** For example, `public.example.com` no longer inherits mTLS from `*.example.com`. If you were counting on that inheritance, configure `client_auth` on the specific site explicitly. ([#&#8203;7920](https://github.com/caddyserver/caddy/issues/7920)) - **Stricter config validation.** Some configs that used to be silently accepted (and probably didn't do what you expected) are now errors: - duplicate `named_routes` ([#&#8203;7800](https://github.com/caddyserver/caddy/issues/7800)) - duplicate `forward_auth` `uri` ([#&#8203;7814](https://github.com/caddyserver/caddy/issues/7814)) - invalid `weighted_round_robin` weights ([#&#8203;7807](https://github.com/caddyserver/caddy/issues/7807)) - a non-integer `browse` `file_limit` ([#&#8203;7988](https://github.com/caddyserver/caddy/issues/7988)) - duplicate or ambiguous `map` inputs ([#&#8203;8067](https://github.com/caddyserver/caddy/issues/8067)) - malformed `map` destination placeholders ([#&#8203;8074](https://github.com/caddyserver/caddy/issues/8074)) - module paths with ambiguous `@` version separators ([#&#8203;7974](https://github.com/caddyserver/caddy/issues/7974)) - **Admin API [`/load`](https://caddyserver.com/docs/api#post-load)** now returns `400` with warnings inside a valid JSON body when a config is invalid. Before, it returned `200` with two concatenated JSON objects. ([#&#8203;7267](https://github.com/caddyserver/caddy/issues/7267)) - **[`method`](https://caddyserver.com/docs/caddyfile/matchers#method) matcher values are normalized to uppercase**, so `method get` now matches `GET` requests. ([#&#8203;7832](https://github.com/caddyserver/caddy/issues/7832)) ##### Security fixes Thank you to everyone who reported responsibly and helped with patches: - reverseproxy: When a route used both [`forward_auth`](https://caddyserver.com/docs/caddyfile/directives/forward_auth) and [`reverse_proxy`](https://caddyserver.com/docs/caddyfile/directives/reverse_proxy), a request could be sent on the wrong upstream connection. Reported by [@&#8203;carlt](https://github.com/carlt), fixed by [@&#8203;WeidiDeng](https://github.com/WeidiDeng). (GHSA-6365-7ppr-5r92, [#&#8203;7859](https://github.com/caddyserver/caddy/issues/7859)) - reverseproxy: Hop-by-hop headers from upstreams are now stripped from `101 Switching Protocols` responses too. Thanks [@&#8203;jirn073-76](https://github.com/jirn073-76). - caddyhttp: [`handle_path`](https://caddyserver.com/docs/caddyfile/directives/handle_path) and [`uri`](https://caddyserver.com/docs/caddyfile/directives/uri) `strip_prefix`/`strip_suffix` now canonicalize the resulting path, so it can't bypass path-based authorization. Thanks [@&#8203;steadytao](https://github.com/steadytao). - caddyhttp: Extended the 2.11.4 header-alias filter to `.` (see above) to prevent bypassing `forward_auth copy_headers` with PHP/FastCGI backends. Thanks [@&#8203;dunglas](https://github.com/dunglas). - caddyhttp: The [`path_regexp`](https://caddyserver.com/docs/caddyfile/matchers#path-regexp) matcher now normalizes Windows backslashes like the `path` matcher does. This completes the fix for CVE-2026-52844. Thanks [@&#8203;thientd](https://github.com/thientd). ([#&#8203;7858](https://github.com/caddyserver/caddy/issues/7858)) - fileserver: Windows 8.3 short names are rejected in every path component, not just the last one. Thanks [@&#8203;DavidCarliez](https://github.com/DavidCarliez). ([#&#8203;7952](https://github.com/caddyserver/caddy/issues/7952)) - fileserver: Fixed ETag collisions between files with different modification times and sizes. Thanks [@&#8203;dunglas](https://github.com/dunglas). - fastcgi: The client's `Proxy` header is no longer passed to backends as `HTTP_PROXY` (HTTPoxy). Thanks [@&#8203;bzyy1024](https://github.com/bzyy1024). ([#&#8203;7934](https://github.com/caddyserver/caddy/issues/7934)) - reverseproxy: Sticky session cookie hashes are compared in constant time. Thanks [@&#8203;alhudz](https://github.com/alhudz). ([#&#8203;7853](https://github.com/caddyserver/caddy/issues/7853)) - admin: Request paths are normalized in the remote admin access check, and origin/host allow-lists compare case-insensitively (defense-in-depth). Thanks [@&#8203;AmariahAK](https://github.com/AmariahAK), [@&#8203;mohammed90](https://github.com/mohammed90), and [@&#8203;hktitof](https://github.com/hktitof). ([#&#8203;7910](https://github.com/caddyserver/caddy/issues/7910), [#&#8203;7973](https://github.com/caddyserver/caddy/issues/7973), [#&#8203;7993](https://github.com/caddyserver/caddy/issues/7993)) - caddyhttp: Oversized request bodies used through placeholders now correctly return `413`. Thanks [@&#8203;hktitof](https://github.com/hktitof). ([#&#8203;7969](https://github.com/caddyserver/caddy/issues/7969)) :warning: These security patches may be breaking if your application relies on the buggy behaviors. :rotating_light: **Notice for Caddy plugin maintainers: Dependabot will probably alert you to the security fixes in Caddy and urge you to upgrade it in your `go.mod` file. Please ONLY upgrade the Caddy dependency if there's a change to an exported API your plugin uses.** Note that doing so now also requires Go 1.26. Thank you to everyone who was involved this release, especially our 40 new contributors! :tada: ##### What's Changed - reverseproxy: replace placeholders specified for sni while using http3 by [@&#8203;WeidiDeng](https://github.com/WeidiDeng) in [#&#8203;7737](https://github.com/caddyserver/caddy/pull/7737) - caddyhttp: add {http.request.proto_name} placeholder for spec-compliant protocol names by [@&#8203;Jualhosting](https://github.com/Jualhosting) in [#&#8203;7782](https://github.com/caddyserver/caddy/pull/7782) - httpcaddyfile: error on duplicate named_routes by [@&#8203;vijayvenkatj](https://github.com/vijayvenkatj) in [#&#8203;7800](https://github.com/caddyserver/caddy/pull/7800) - cmd: colored error message in WrapCommandFuncForCobra ([#&#8203;7760](https://github.com/caddyserver/caddy/issues/7760)) by [@&#8203;u5surf](https://github.com/u5surf) in [#&#8203;7768](https://github.com/caddyserver/caddy/pull/7768) - chore: add missing "is" in SECURITY.md by [@&#8203;AliMickey](https://github.com/AliMickey) in [#&#8203;7802](https://github.com/caddyserver/caddy/pull/7802) - reverseproxy: validate on weighted_round_robin loadbalancing policy by [@&#8203;vijayvenkatj](https://github.com/vijayvenkatj) in [#&#8203;7807](https://github.com/caddyserver/caddy/pull/7807) - forwardauth: error on duplicate uri subdirective by [@&#8203;vijayvenkatj](https://github.com/vijayvenkatj) in [#&#8203;7814](https://github.com/caddyserver/caddy/pull/7814) - encode: add standard benchmark and conformance harness by [@&#8203;ottenhoff](https://github.com/ottenhoff) in [#&#8203;7804](https://github.com/caddyserver/caddy/pull/7804) - caddyhttp: restore allow_underscore_in_headers server option by [@&#8203;bluegate-studio](https://github.com/bluegate-studio) in [#&#8203;7809](https://github.com/caddyserver/caddy/pull/7809) - rewrite: fix wrong index check in trimPathPrefix by [@&#8203;alhudz](https://github.com/alhudz) in [#&#8203;7812](https://github.com/caddyserver/caddy/pull/7812) - intercept: fix replace_status being silently dropped by [@&#8203;oksusucha](https://github.com/oksusucha) in [#&#8203;7810](https://github.com/caddyserver/caddy/pull/7810) - fileserver: append repeated hide subdirectives instead of overwriting by [@&#8203;luccinmasirika](https://github.com/luccinmasirika) in [#&#8203;7817](https://github.com/caddyserver/caddy/pull/7817) - rewrite: scope keyed query replace to its named key by [@&#8203;alhudz](https://github.com/alhudz) in [#&#8203;7818](https://github.com/caddyserver/caddy/pull/7818) - reverseproxy: log status 499 instead of 0 when client disconnects by [@&#8203;larrasket](https://github.com/larrasket) in [#&#8203;7827](https://github.com/caddyserver/caddy/pull/7827) - tracing: fix BatchSpanProcessor goroutine leak on config reload by [@&#8203;Dean2026](https://github.com/Dean2026) in [#&#8203;7826](https://github.com/caddyserver/caddy/pull/7826) - caddyhttp: normalize method names to uppercase in MatchMethod.Provision by [@&#8203;yintaisha](https://github.com/yintaisha) in [#&#8203;7832](https://github.com/caddyserver/caddy/pull/7832) - caddyhttp: add URL pattern request matcher by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;7787](https://github.com/caddyserver/caddy/pull/7787) - caddyhttp: fix escaped path matcher over-matching longer paths by [@&#8203;alhudz](https://github.com/alhudz) in [#&#8203;7828](https://github.com/caddyserver/caddy/pull/7828) - core: preserve metrics registry in Context.WithValue by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;7861](https://github.com/caddyserver/caddy/pull/7861) - reverseproxy: compare sticky-session cookie hash in constant time by [@&#8203;alhudz](https://github.com/alhudz) in [#&#8203;7853](https://github.com/caddyserver/caddy/pull/7853) - reverseproxy: fix misleading handle_response error for extra matcher args by [@&#8203;TowyTowy](https://github.com/TowyTowy) in [#&#8203;7869](https://github.com/caddyserver/caddy/pull/7869) - reverseproxy: save dial info in a context key instead of a variable k… by [@&#8203;WeidiDeng](https://github.com/WeidiDeng) in [#&#8203;7859](https://github.com/caddyserver/caddy/pull/7859) - caddyhttp: fix path_regexp (MatchPathRE) Windows backslash bypass by [@&#8203;thientd](https://github.com/thientd) in [#&#8203;7858](https://github.com/caddyserver/caddy/pull/7858) - intercept: fix misleading handle_response error for extra matcher args by [@&#8203;TowyTowy](https://github.com/TowyTowy) in [#&#8203;7871](https://github.com/caddyserver/caddy/pull/7871) - build(deps): bump cel-go from v0.28.1 to v0.29.2 by [@&#8203;techknowlogick](https://github.com/techknowlogick) in [#&#8203;7872](https://github.com/caddyserver/caddy/pull/7872) - reverseproxy: fix broken reservoir sampling in random_choose policy by [@&#8203;TowyTowy](https://github.com/TowyTowy) in [#&#8203;7873](https://github.com/caddyserver/caddy/pull/7873) - caddyfile: treat quoted braces as literal arguments by [@&#8203;elee1766](https://github.com/elee1766) in [#&#8203;7875](https://github.com/caddyserver/caddy/pull/7875) - logging: hash query parameter values in QueryFilter by [@&#8203;PichuChen](https://github.com/PichuChen) in [#&#8203;7884](https://github.com/caddyserver/caddy/pull/7884) - chore: fix sabotage spelling in nolint comments by [@&#8203;futurehua](https://github.com/futurehua) in [#&#8203;7892](https://github.com/caddyserver/caddy/pull/7892) - pki: Handle error immediately after reading root from disk by [@&#8203;hslatman](https://github.com/hslatman) in [#&#8203;7896](https://github.com/caddyserver/caddy/pull/7896) - log: support `d` (day) in `roll_interval` directive by [@&#8203;mohammed90](https://github.com/mohammed90) in [#&#8203;7900](https://github.com/caddyserver/caddy/pull/7900) - deps: update GitHub Actions and Go modules by [@&#8203;steadytao](https://github.com/steadytao) in [#&#8203;7876](https://github.com/caddyserver/caddy/pull/7876) - build(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;7908](https://github.com/caddyserver/caddy/pull/7908) - core: reduce QUIC initial packet size for low-MTU paths by [@&#8203;Salynn](https://github.com/Salynn) in [#&#8203;7886](https://github.com/caddyserver/caddy/pull/7886) - rewrite: preserve non-canonical path encoding after uri replace by [@&#8203;larrasket](https://github.com/larrasket) in [#&#8203;7907](https://github.com/caddyserver/caddy/pull/7907) - caddyhttp: use canonical header key casing to avoid re-canonicalization by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;7911](https://github.com/caddyserver/caddy/pull/7911) - caddyconfig: Register nested named-route invokes transitively by [@&#8203;SillyZir](https://github.com/SillyZir) in [#&#8203;7898](https://github.com/caddyserver/caddy/pull/7898) - encode: reduce allocations in AcceptedEncodings by [@&#8203;jvoisin](https://github.com/jvoisin) in [#&#8203;7847](https://github.com/caddyserver/caddy/pull/7847) - encode: flush headers immediately for server-sent events responses by [@&#8203;SillyZir](https://github.com/SillyZir) in [#&#8203;7905](https://github.com/caddyserver/caddy/pull/7905) - fileserver: speed up directory browsing for large directories by [@&#8203;firefart](https://github.com/firefart) in [#&#8203;7903](https://github.com/caddyserver/caddy/pull/7903) - caddyauth: isolate provider responses to prevent cross-provider clobbering by [@&#8203;SillyZir](https://github.com/SillyZir) in [#&#8203;7904](https://github.com/caddyserver/caddy/pull/7904) - log: don't allow overwriting singly-assigned vals by [@&#8203;mohammed90](https://github.com/mohammed90) in [#&#8203;7927](https://github.com/caddyserver/caddy/pull/7927) - caddyconfig: cancel HTTP loader requests with context by [@&#8203;cuishuang](https://github.com/cuishuang) in [#&#8203;7918](https://github.com/caddyserver/caddy/pull/7918) - feat(fastcgi): populate SERVER_ADDR by default by [@&#8203;renich](https://github.com/renich) in [#&#8203;7912](https://github.com/caddyserver/caddy/pull/7912) - reverseproxy: reduce allocation/CPU overhead in request hot paths by [@&#8203;jvoisin](https://github.com/jvoisin) in [#&#8203;7925](https://github.com/caddyserver/caddy/pull/7925) - reverseproxy: preallocate upstream slices with known sizes by [@&#8203;jvoisin](https://github.com/jvoisin) in [#&#8203;7926](https://github.com/caddyserver/caddy/pull/7926) - network_proxy: reject proxy URLs that resolve to a port with no host by [@&#8203;r0h1tb](https://github.com/r0h1tb) in [#&#8203;7922](https://github.com/caddyserver/caddy/pull/7922) - caddyhttp: log recovered handler panics at ERROR level by [@&#8203;ousamabenyounes](https://github.com/ousamabenyounes) in [#&#8203;7924](https://github.com/caddyserver/caddy/pull/7924) - caddyhttp: allocate the request UUID lazily instead of on every request by [@&#8203;jvoisin](https://github.com/jvoisin) in [#&#8203;7936](https://github.com/caddyserver/caddy/pull/7936) - caddyhttp: shield specific hostnames from a covering wildcard's client auth by [@&#8203;SillyZir](https://github.com/SillyZir) in [#&#8203;7920](https://github.com/caddyserver/caddy/pull/7920) - reverseproxy: isolate active health-check state per distinct check config by [@&#8203;SillyZir](https://github.com/SillyZir) in [#&#8203;7916](https://github.com/caddyserver/caddy/pull/7916) - logging: add set_cookie log filter for Set-Cookie response headers by [@&#8203;steffenbusch](https://github.com/steffenbusch) in [#&#8203;7888](https://github.com/caddyserver/caddy/pull/7888) - caddyhttp: fix url_pattern authorization bypass via encoded-slash traversal by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;7941](https://github.com/caddyserver/caddy/pull/7941) - fix: close resources on error paths by [@&#8203;ittakestwo123](https://github.com/ittakestwo123) in [#&#8203;7940](https://github.com/caddyserver/caddy/pull/7940) - fastcgi: fix HTTPoxy vulnerability by [@&#8203;bzyy1024](https://github.com/bzyy1024) in [#&#8203;7934](https://github.com/caddyserver/caddy/pull/7934) - caddyhttp: mitigate slowloris via idle read/write deadlines by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;7913](https://github.com/caddyserver/caddy/pull/7913) - chore: fix lint errors from newer golangci-lint by [@&#8203;faiyazrahmann](https://github.com/faiyazrahmann) in [#&#8203;7958](https://github.com/caddyserver/caddy/pull/7958) - pki: honor skip_install_trust for explicit tls internal issuers by [@&#8203;gautamrizwani](https://github.com/gautamrizwani) in [#&#8203;7894](https://github.com/caddyserver/caddy/pull/7894) - caddyfile: clarify ArgErr documentation by [@&#8203;0jaspahwa](https://github.com/0jaspahwa) in [#&#8203;7960](https://github.com/caddyserver/caddy/pull/7960) - rewrite: fix URI splitting when a query or fragment arrives via a placeholder by [@&#8203;francislavoie](https://github.com/francislavoie) in [#&#8203;7947](https://github.com/caddyserver/caddy/pull/7947) - admin: normalize request path in remote admin access-control check (defense-in-depth) by [@&#8203;AmariahAK](https://github.com/AmariahAK) in [#&#8203;7910](https://github.com/caddyserver/caddy/pull/7910) - fileserver: reject short names in every path component by [@&#8203;DavidCarliez](https://github.com/DavidCarliez) in [#&#8203;7952](https://github.com/caddyserver/caddy/pull/7952) - rewrite: fix strip_path_suffix ignoring percent-encoding by [@&#8203;TowyTowy](https://github.com/TowyTowy) in [#&#8203;7877](https://github.com/caddyserver/caddy/pull/7877) - admin: stabilise log redaction test by [@&#8203;steadytao](https://github.com/steadytao) in [#&#8203;7942](https://github.com/caddyserver/caddy/pull/7942) - chore: fix canonicalheader failures by [@&#8203;steadytao](https://github.com/steadytao) in [#&#8203;7964](https://github.com/caddyserver/caddy/pull/7964) - cmd: upgrade automemlimit to v1.0.0 by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;7978](https://github.com/caddyserver/caddy/pull/7978) - caddy: fix ParseNetworkAddress port-range span off-by-one by [@&#8203;mohammed90](https://github.com/mohammed90) in [#&#8203;7975](https://github.com/caddyserver/caddy/pull/7975) - usagepool: avoid lock inversion after constructor failure by [@&#8203;kojah](https://github.com/kojah) in [#&#8203;7968](https://github.com/caddyserver/caddy/pull/7968) - cmd: reject ambiguous module version separators by [@&#8203;mohammed90](https://github.com/mohammed90) in [#&#8203;7974](https://github.com/caddyserver/caddy/pull/7974) - admin: fix origin allow-list host comparison to be case-insensitive by [@&#8203;mohammed90](https://github.com/mohammed90) in [#&#8203;7973](https://github.com/caddyserver/caddy/pull/7973) - caddyfile: fix importGraph self-loop and stale-edge bugs by [@&#8203;mohammed90](https://github.com/mohammed90) in [#&#8203;7971](https://github.com/caddyserver/caddy/pull/7971) - caddyhttp: remove unused QUICConfig from the HTTP/3 server by [@&#8203;faiyazrahmann](https://github.com/faiyazrahmann) in [#&#8203;7980](https://github.com/caddyserver/caddy/pull/7980) - fileserver: reject non-integer browse file_limit by [@&#8203;SashaMIT](https://github.com/SashaMIT) in [#&#8203;7988](https://github.com/caddyserver/caddy/pull/7988) - caddyhttp: surface write timeout errors in access log by [@&#8203;faiyazrahmann](https://github.com/faiyazrahmann) in [#&#8203;7945](https://github.com/caddyserver/caddy/pull/7945) - admin: fix host allow-list comparison to be case-insensitive by [@&#8203;hktitof](https://github.com/hktitof) in [#&#8203;7993](https://github.com/caddyserver/caddy/pull/7993) - caddytls: synchronize storage cleaner with TLS.Stop via context and WaitGroup by [@&#8203;jum](https://github.com/jum) in [#&#8203;7954](https://github.com/caddyserver/caddy/pull/7954) - httpcaddyfile: give each adaptation its own directive order by [@&#8203;faiyazrahmann](https://github.com/faiyazrahmann) in [#&#8203;7995](https://github.com/caddyserver/caddy/pull/7995) - listen: don't wedge a reloaded listener sharing a socket on Windows by [@&#8203;alexandre-daubois](https://github.com/alexandre-daubois) in [#&#8203;7999](https://github.com/caddyserver/caddy/pull/7999) - caddyhttp: demote Alt-Svc ErrNoAltSvcPort to debug level by [@&#8203;jum](https://github.com/jum) in [#&#8203;8000](https://github.com/caddyserver/caddy/pull/8000) - events: skip dispatch setup when nothing is subscribed by [@&#8203;u5surf](https://github.com/u5surf) in [#&#8203;7997](https://github.com/caddyserver/caddy/pull/7997) - reverseproxy: replace only known placeholders in health check body by [@&#8203;IslamElsayed](https://github.com/IslamElsayed) in [#&#8203;8003](https://github.com/caddyserver/caddy/pull/8003) - acmeserver: say when the CA database is locked by another process by [@&#8203;faiyazrahmann](https://github.com/faiyazrahmann) in [#&#8203;8007](https://github.com/caddyserver/caddy/pull/8007) - fix: require module path boundaries when matching packages by [@&#8203;wangjingshuiku](https://github.com/wangjingshuiku) in [#&#8203;7957](https://github.com/caddyserver/caddy/pull/7957) - caddyhttp: preserve unknown placeholders in static response headers by [@&#8203;hktitof](https://github.com/hktitof) in [#&#8203;8014](https://github.com/caddyserver/caddy/pull/8014) - build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;7984](https://github.com/caddyserver/caddy/pull/7984) - reverseproxy: propagate TCP half-close on upgraded streams by [@&#8203;btncwn](https://github.com/btncwn) in [#&#8203;8027](https://github.com/caddyserver/caddy/pull/8027) - build(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;8028](https://github.com/caddyserver/caddy/pull/8028) - caddyfile: Expand imports inside named routes by [@&#8203;XiaoleC05](https://github.com/XiaoleC05) in [#&#8203;7986](https://github.com/caddyserver/caddy/pull/7986) - chore(deps): bump cel-go and switch import to new url by [@&#8203;techknowlogick](https://github.com/techknowlogick) in [#&#8203;8030](https://github.com/caddyserver/caddy/pull/8030) - core: synchronize Stop with concurrent config reloads by [@&#8203;H-XX-D](https://github.com/H-XX-D) in [#&#8203;8038](https://github.com/caddyserver/caddy/pull/8038) - reverse_proxy with versions 3 silently ignores tls_trust_pool and verifies against the system roots by [@&#8203;tippexs](https://github.com/tippexs) in [#&#8203;8042](https://github.com/caddyserver/caddy/pull/8042) - admin: fix warnings and status code in /load API by [@&#8203;amirdaraby](https://github.com/amirdaraby) in [#&#8203;7267](https://github.com/caddyserver/caddy/pull/7267) - fastcgi: explain 411 responses for unknown-length bodies by [@&#8203;Rohilalala](https://github.com/Rohilalala) in [#&#8203;7956](https://github.com/caddyserver/caddy/pull/7956) - Move websocket header normalization later by [@&#8203;nfreya](https://github.com/nfreya) in [#&#8203;7921](https://github.com/caddyserver/caddy/pull/7921) - chore: remove AI moderator workflow by [@&#8203;mohammed90](https://github.com/mohammed90) in [#&#8203;8059](https://github.com/caddyserver/caddy/pull/8059) - caddyhttp: surface 413 for oversized request body placeholders by [@&#8203;hktitof](https://github.com/hktitof) in [#&#8203;7969](https://github.com/caddyserver/caddy/pull/7969) - reverseproxy: Fix partial response not flushed to clients by [@&#8203;WeidiDeng](https://github.com/WeidiDeng) in [#&#8203;7849](https://github.com/caddyserver/caddy/pull/7849) - caddyhttp: fix randString sameCase dictionary to match its docs by [@&#8203;mohammed90](https://github.com/mohammed90) in [#&#8203;7972](https://github.com/caddyserver/caddy/pull/7972) - requestbody: replace only known placeholders in the set body by [@&#8203;hktitof](https://github.com/hktitof) in [#&#8203;8008](https://github.com/caddyserver/caddy/pull/8008) - internal: fix `MaxSizeSubjectsListForLog` off-by-one when `maxToDisplay` is `0` by [@&#8203;mohammed90](https://github.com/mohammed90) in [#&#8203;7970](https://github.com/caddyserver/caddy/pull/7970) - caddyauth: only replace known placeholders in basic auth credentials by [@&#8203;hktitof](https://github.com/hktitof) in [#&#8203;8017](https://github.com/caddyserver/caddy/pull/8017) - map: Distinguish duplicate literal and regexp inputs by [@&#8203;Indra55](https://github.com/Indra55) in [#&#8203;8067](https://github.com/caddyserver/caddy/pull/8067) - map: reject malformed destination placeholders by [@&#8203;sleet0922](https://github.com/sleet0922) in [#&#8203;8074](https://github.com/caddyserver/caddy/pull/8074) - httpcaddyfile: new `tls_automate_names` global option by [@&#8203;IslamElsayed](https://github.com/IslamElsayed) in [#&#8203;8015](https://github.com/caddyserver/caddy/pull/8015) - build: bump all dependencies - (Go 1.26 floor) by [@&#8203;steadytao](https://github.com/steadytao) in [#&#8203;8056](https://github.com/caddyserver/caddy/pull/8056) - caddyhttp: wait for servers from previous configs on exit by [@&#8203;dunglas](https://github.com/dunglas) in [#&#8203;8009](https://github.com/caddyserver/caddy/pull/8009) - caddyhttp: use errors.AsType for request body limit errors by [@&#8203;mholt](https://github.com/mholt) in [#&#8203;8090](https://github.com/caddyserver/caddy/pull/8090) - ci: pin cosign to v2 for release signing by [@&#8203;francislavoie](https://github.com/francislavoie) in [#&#8203;8092](https://github.com/caddyserver/caddy/pull/8092) ##### New Contributors - [@&#8203;vijayvenkatj](https://github.com/vijayvenkatj) made their first contribution in [#&#8203;7800](https://github.com/caddyserver/caddy/pull/7800) - [@&#8203;AliMickey](https://github.com/AliMickey) made their first contribution in [#&#8203;7802](https://github.com/caddyserver/caddy/pull/7802) - [@&#8203;bluegate-studio](https://github.com/bluegate-studio) made their first contribution in [#&#8203;7809](https://github.com/caddyserver/caddy/pull/7809) - [@&#8203;alhudz](https://github.com/alhudz) made their first contribution in [#&#8203;7812](https://github.com/caddyserver/caddy/pull/7812) - [@&#8203;oksusucha](https://github.com/oksusucha) made their first contribution in [#&#8203;7810](https://github.com/caddyserver/caddy/pull/7810) - [@&#8203;luccinmasirika](https://github.com/luccinmasirika) made their first contribution in [#&#8203;7817](https://github.com/caddyserver/caddy/pull/7817) - [@&#8203;larrasket](https://github.com/larrasket) made their first contribution in [#&#8203;7827](https://github.com/caddyserver/caddy/pull/7827) - [@&#8203;Dean2026](https://github.com/Dean2026) made their first contribution in [#&#8203;7826](https://github.com/caddyserver/caddy/pull/7826) - [@&#8203;yintaisha](https://github.com/yintaisha) made their first contribution in [#&#8203;7832](https://github.com/caddyserver/caddy/pull/7832) - [@&#8203;TowyTowy](https://github.com/TowyTowy) made their first contribution in [#&#8203;7869](https://github.com/caddyserver/caddy/pull/7869) - [@&#8203;thientd](https://github.com/thientd) made their first contribution in [#&#8203;7858](https://github.com/caddyserver/caddy/pull/7858) - [@&#8203;PichuChen](https://github.com/PichuChen) made their first contribution in [#&#8203;7884](https://github.com/caddyserver/caddy/pull/7884) - [@&#8203;futurehua](https://github.com/futurehua) made their first contribution in [#&#8203;7892](https://github.com/caddyserver/caddy/pull/7892) - [@&#8203;Salynn](https://github.com/Salynn) made their first contribution in [#&#8203;7886](https://github.com/caddyserver/caddy/pull/7886) - [@&#8203;SillyZir](https://github.com/SillyZir) made their first contribution in [#&#8203;7898](https://github.com/caddyserver/caddy/pull/7898) - [@&#8203;jvoisin](https://github.com/jvoisin) made their first contribution in [#&#8203;7847](https://github.com/caddyserver/caddy/pull/7847) - [@&#8203;firefart](https://github.com/firefart) made their first contribution in [#&#8203;7903](https://github.com/caddyserver/caddy/pull/7903) - [@&#8203;renich](https://github.com/renich) made their first contribution in [#&#8203;7912](https://github.com/caddyserver/caddy/pull/7912) - [@&#8203;r0h1tb](https://github.com/r0h1tb) made their first contribution in [#&#8203;7922](https://github.com/caddyserver/caddy/pull/7922) - [@&#8203;ousamabenyounes](https://github.com/ousamabenyounes) made their first contribution in [#&#8203;7924](https://github.com/caddyserver/caddy/pull/7924) - [@&#8203;ittakestwo123](https://github.com/ittakestwo123) made their first contribution in [#&#8203;7940](https://github.com/caddyserver/caddy/pull/7940) - [@&#8203;bzyy1024](https://github.com/bzyy1024) made their first contribution in [#&#8203;7934](https://github.com/caddyserver/caddy/pull/7934) - [@&#8203;faiyazrahmann](https://github.com/faiyazrahmann) made their first contribution in [#&#8203;7958](https://github.com/caddyserver/caddy/pull/7958) - [@&#8203;gautamrizwani](https://github.com/gautamrizwani) made their first contribution in [#&#8203;7894](https://github.com/caddyserver/caddy/pull/7894) - [@&#8203;0jaspahwa](https://github.com/0jaspahwa) made their first contribution in [#&#8203;7960](https://github.com/caddyserver/caddy/pull/7960) - [@&#8203;AmariahAK](https://github.com/AmariahAK) made their first contribution in [#&#8203;7910](https://github.com/caddyserver/caddy/pull/7910) - [@&#8203;DavidCarliez](https://github.com/DavidCarliez) made their first contribution in [#&#8203;7952](https://github.com/caddyserver/caddy/pull/7952) - [@&#8203;kojah](https://github.com/kojah) made their first contribution in [#&#8203;7968](https://github.com/caddyserver/caddy/pull/7968) - [@&#8203;SashaMIT](https://github.com/SashaMIT) made their first contribution in [#&#8203;7988](https://github.com/caddyserver/caddy/pull/7988) - [@&#8203;hktitof](https://github.com/hktitof) made their first contribution in [#&#8203;7993](https://github.com/caddyserver/caddy/pull/7993) - [@&#8203;IslamElsayed](https://github.com/IslamElsayed) made their first contribution in [#&#8203;8003](https://github.com/caddyserver/caddy/pull/8003) - [@&#8203;wangjingshuiku](https://github.com/wangjingshuiku) made their first contribution in [#&#8203;7957](https://github.com/caddyserver/caddy/pull/7957) - [@&#8203;btncwn](https://github.com/btncwn) made their first contribution in [#&#8203;8027](https://github.com/caddyserver/caddy/pull/8027) - [@&#8203;XiaoleC05](https://github.com/XiaoleC05) made their first contribution in [#&#8203;7986](https://github.com/caddyserver/caddy/pull/7986) - [@&#8203;H-XX-D](https://github.com/H-XX-D) made their first contribution in [#&#8203;8038](https://github.com/caddyserver/caddy/pull/8038) - [@&#8203;tippexs](https://github.com/tippexs) made their first contribution in [#&#8203;8042](https://github.com/caddyserver/caddy/pull/8042) - [@&#8203;amirdaraby](https://github.com/amirdaraby) made their first contribution in [#&#8203;7267](https://github.com/caddyserver/caddy/pull/7267) - [@&#8203;Rohilalala](https://github.com/Rohilalala) made their first contribution in [#&#8203;7956](https://github.com/caddyserver/caddy/pull/7956) - [@&#8203;nfreya](https://github.com/nfreya) made their first contribution in [#&#8203;7921](https://github.com/caddyserver/caddy/pull/7921) - [@&#8203;Indra55](https://github.com/Indra55) made their first contribution in [#&#8203;8067](https://github.com/caddyserver/caddy/pull/8067) **Full Changelog**: <https://github.com/caddyserver/caddy/compare/v2.11.4...v2.11.6> ### [`v2.11.5`](https://github.com/caddyserver/caddy/compare/v2.11.4...v2.11.5) [Compare Source](https://github.com/caddyserver/caddy/compare/v2.11.4...v2.11.5) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Berlin) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNDIuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjE0Mi4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
fix(deps): update module github.com/caddyserver/caddy/v2 to v2.11.7
Some checks failed
test_and_report / Test and report maintainability of ldap-cli (push) Failing after 1m2s
2bd18becb0
renovate scheduled this pull request to auto merge when all checks succeed 2026-10-07 17:25:04 +00:00
Author
Collaborator

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.


  • Branch has one or more failed status checks
### Branch automerge failure This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead. ___ * Branch has one or more failed status checks
Some checks failed
test_and_report / Test and report maintainability of ldap-cli (push) Failing after 1m2s
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/all-patch:renovate/all-patch
git switch renovate/all-patch

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/all-patch
git switch renovate/all-patch
git rebase main
git switch main
git merge --ff-only renovate/all-patch
git switch renovate/all-patch
git rebase main
git switch main
git merge --no-ff renovate/all-patch
git switch main
git merge --squash renovate/all-patch
git switch main
git merge --ff-only renovate/all-patch
git switch main
git merge renovate/all-patch
git push origin main
Sign in to join this conversation.
No description provided.