Skip to content

Update dependency caddyserver/caddy to v2.11.6 - #301

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/caddyserver-caddy-2.x
Oct 1, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/caddyserver-caddy-2.x

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
caddyserver/caddy patch v2.11.4 → v2.11.6

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

caddyserver/caddy (caddyserver/caddy)

v2.11.6

Compare Source

This patch release contains a large number of minor and some noticeable enhancements and bug fixes. Thank you to everyone who contributed or spent their LLM tokens responsibly to help with this release!

We have much more in the pipeline still, as AI has made contributions of all quality levels cheap and easy. We will be trying to go through them as quickly and efficiently as we can.

Huge thank you to our sponsors for keeping the project alive with resources, and for our maintainers who triage and assist tirelessly in this relentless new age of AI.

⚠️ Please read the breaking changes below before upgrading. Most of them come from security hardening, and most configs won't notice. If you were relying on one of the old behaviors, though, you'll want to know about it.

Highlights

  • New url_pattern request matcher: Match requests with the URLPattern standard, the same syntax used by browsers (JS) and many web frameworks. It supports named groups, wildcards, and regexp components. Captured groups become placeholders ({http.url_pattern.<component>.<group>}), and there's a matching url_pattern CEL function too. Thanks @​dunglas! (#​7787)
  • Slowloris mitigation: New idle read/write timeouts reset on every successful read or write. A stalled connection gets cut off, and a slow one that's still making progress is left alone. You can also set optional minimum transfer rates, and there's a new timeouts handler directive for per-route tuning. (#​7913)
  • New tls_automate_names global option: Manage certificates for names without serving them in a site block. (#​8015)
  • New expected_underscore_headers server option: If dropping header fields with underscores in 2.11.4 broke your app, you can now list the specific headers to keep. (#​7809)
  • HTTP/3 over Tailscale and other low-MTU links now works, because the initial QUIC packet size is smaller. (#​7886)
  • Reverse proxy got more love:
    • partial responses are flushed to clients properly (#​7849)
    • TCP half-close is propagated on upgraded streams (#​8027)
    • versions 3 upstreams now honor tls_trust_pool (#​8042)
    • active health check state is kept separate per check config, so one handler's failing probes don't mark the upstream down for everyone else (#​7916)
    • the random_choose policy distributes correctly now (#​7873)
  • Server-sent events behind encode now stream immediately instead of being buffered. (#​7905)
  • Graceful shutdown now waits for servers left over from previous configs, so long-lived responses that started before a reload aren't cut off at exit. (#​8009)
  • Caddyfile: import now works inside named routes (#​7986), and quoted braces are treated as literal arguments (#​7875).
  • Logging:
  • Performance: fewer allocations in request hot paths, encoding negotiation, and the reverse proxy, from @​jvoisin and @​dunglas. Directory browsing is much faster for large directories. (#​7847, #​7903, #​7911, #​7925, #​7926, #​7936)
  • Other new stuff:
    • {http.request.proto_name} placeholder (#​7782)
    • FastCGI populates SERVER_ADDR (#​7912)
    • multiple authentication providers no longer clobber each other's responses (#​7904)

⚠️ Breaking changes

  • Go 1.26 is now the minimum version for building Caddy and plugins. (#​8056)
  • Request headers are limited to 16 KiB by default. Before, we used Go's 1 MB default. Requests with larger headers (giant cookies, oversized tokens, etc.) will now get 431 Request Header Fields Too Large. If you need more, raise it with the max_header_size server option.
  • New 1-minute idle read/write timeouts by default. If a request body read or a response write stalls (makes no progress at all) for longer than that, the connection is aborted. Pauses between writes, like with SSE, don't count. Some long-lived streams where the client goes quiet mid-body may be affected. You can tune these with read_body_idle and write_idle in the timeouts server option, or per-route with the timeouts directive. (#​7913)
  • Request header fields containing . are now dropped, the same way underscores were in 2.11.4. PHP folds . to _, so these could be used to impersonate legitimate headers. If you need specific ones, allow them with the new expected_dot_headers server option.
  • A wildcard site's client_auth no longer applies to more specific hostnames that have their own site blocks. For example, public.example.com no longer inherits mTLS from *.example.com. If you were counting on that inheritance, configure client_auth on the specific site explicitly. (#​7920)
  • Stricter config validation. Some configs that used to be silently accepted (and probably didn't do what you expected) are now errors:
    • duplicate named_routes (#​7800)
    • duplicate forward_auth uri (#​7814)
    • invalid weighted_round_robin weights (#​7807)
    • a non-integer browse file_limit (#​7988)
    • duplicate or ambiguous map inputs (#​8067)
    • malformed map destination placeholders (#​8074)
    • module paths with ambiguous @ version separators (#​7974)
  • Admin API /load now returns 400 with warnings inside a valid JSON body when a config is invalid. Before, it returned 200 with two concatenated JSON objects. (#​7267)
  • method matcher values are normalized to uppercase, so method get now matches GET requests. (#​7832)

Security fixes

Thank you to everyone who reported responsibly and helped with patches:

  • reverseproxy: When a route used both forward_auth and reverse_proxy, a request could be sent on the wrong upstream connection. Reported by @​carlt, fixed by @​WeidiDeng. (GHSA-6365-7ppr-5r92, #​7859)
  • reverseproxy: Hop-by-hop headers from upstreams are now stripped from 101 Switching Protocols responses too. Thanks @​jirn073-76.
  • caddyhttp: handle_path and uri strip_prefix/strip_suffix now canonicalize the resulting path, so it can't bypass path-based authorization. Thanks @​steadytao.
  • caddyhttp: Extended the 2.11.4 header-alias filter to . (see above) to prevent bypassing forward_auth copy_headers with PHP/FastCGI backends. Thanks @​dunglas.
  • caddyhttp: The path_regexp matcher now normalizes Windows backslashes like the path matcher does. This completes the fix for CVE-2026-52844. Thanks @​thientd. (#​7858)
  • fileserver: Windows 8.3 short names are rejected in every path component, not just the last one. Thanks @​DavidCarliez. (#​7952)
  • fileserver: Fixed ETag collisions between files with different modification times and sizes. Thanks @​dunglas.
  • fastcgi: The client's Proxy header is no longer passed to backends as HTTP_PROXY (HTTPoxy). Thanks @​bzyy1024. (#​7934)
  • reverseproxy: Sticky session cookie hashes are compared in constant time. Thanks @​alhudz. (#​7853)
  • admin: Request paths are normalized in the remote admin access check, and origin/host allow-lists compare case-insensitively (defense-in-depth). Thanks @​AmariahAK, @​mohammed90, and @​hktitof. (#​7910, #​7973, #​7993)
  • caddyhttp: Oversized request bodies used through placeholders now correctly return 413. Thanks @​hktitof. (#​7969)

⚠️ These security patches may be breaking if your application relies on the buggy behaviors.

🚨 Notice for Caddy plugin maintainers: Dependabot will probably alert you to the security fixes in Caddy and urge you to upgrade it in your go.mod file. Please ONLY upgrade the Caddy dependency if there's a change to an exported API your plugin uses. Note that doing so now also requires Go 1.26.

Thank you to everyone who was involved this release, especially our 40 new contributors! 🎉

What's Changed

New Contributors

Full Changelog: caddyserver/caddy@v2.11.4...v2.11.6


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • On day 1 of the month, every 3 months (* * 1 */3 *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) October 1, 2026 17:15
@renovate
renovate Bot force-pushed the renovate/caddyserver-caddy-2.x branch from b790b68 to 6c54d9f Compare October 1, 2026 17:15
@renovate
renovate Bot merged commit 72c46c4 into main Oct 1, 2026
14 checks passed
@renovate
renovate Bot deleted the renovate/caddyserver-caddy-2.x branch October 1, 2026 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants