Last 7 days
0
Features: 0
Changes: 0
Fixes: 0
Deprecations: 0
Extensible web server with automatic HTTPS and modern protocol support.
Latest Caddy changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Caddy release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
0
0
2
4
Added several security fixes including path matcher backslash normalization, header underscore handling, placeholder re‑expansion prevention, and improved HTML stripping (may be breaking for dependent code).
Patched multiple security vulnerabilities, including fastcgi execution, admin socket auth bypasses, and upstream quic go/CertMagic bugs.
Enhanced reverse proxy: fixed health‑check port handling, added passive health checking via dynamic upstream tracking, prevented body‑close on retries, and introduced query‑escaping when PROXY protocol is enabled
Added multiple security fixes addressing CVE‑2026‑27586 through CVE‑2026‑27585, including TLS client auth and host/path matcher hardening.