Caddy version lifecycle

tool · Caddy Server

Current status

supported

Supported version lines, end-of-life status, and latest releases for Caddy — derived from official vendor sources, not third-party EOL aggregators.

Caddy is an extensible, open-source web server and reverse proxy with automatic HTTPS.

Security: 12 tracked advisories · 1 in CISA KEV. Details below — lifecycle and vulnerability status are separate.

Official site →

Version lines

20

Supported

1

EOL lines

19

Latest stable

2.11.4

2026-06-03

Releases tracked

87

At a glance

Latest release

2.11.4

Line 2.11

Recommended support line

2.11

standard support

Status

STANDARD SUPPORT

Newest supported: 2.11

EOL

Not published

Exact date not officially published

EOL lines include 2.10, 2.9, 2.8, 2.7, 2.6 (+14 more).

Recommended line: 2.11 (newest supported line with lowest lifecycle risk — not blindly “latest”).

Supported versions

1 currently supported release line.

Version lineLifecycleLatest releaseReleasedEOLRisk
2.11
standard supportlow
2.11.42026-06-03Not officially publishedlow

End-of-life versions

Historical and unsupported release lines. Exact EOL dates shown only when published by the vendor.

Version lineLatest releaseLifecycleEOLRisk
2.102.10.2
end of lifehigh
2026-02-23high
2.92.9.1
end of lifehigh
2025-04-18high
2.82.8.4
end of lifehigh
2024-12-31high
2.72.7.6
end of lifehigh
2024-05-29high
2.62.6.4
end of lifehigh
2023-08-02high
2.52.5.2
end of lifehigh
2022-09-20high
2.42.4.6
end of lifehigh
2022-04-25high
2.32.3.0
end of lifehigh
2021-05-10high
2.22.2.1
end of lifehigh
2021-01-01high
2.12.1.1
end of lifehigh
2020-09-24high
2.02.0.0
end of lifehigh
2020-06-26high
1.01.0.4
end of lifehigh
2020-05-04high
0.110.11.5
end of lifehigh
2019-04-24high
0.100.10.14
end of lifehigh
2018-05-10high
0.90.9.5
end of lifehigh
2017-04-20high
0.80.8.3
end of lifehigh
2016-07-19high
0.70.7.6
end of lifehigh
2015-12-04high
0.60.6.0
end of lifehigh
2015-05-25high
0.50.5.1
end of lifehigh
2015-05-07high

Lifecycle overview

Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.

  • 2.11standard support
    standard support
  • 2.10end of life · EOL 2026-02-23
    standard supportend of life
  • 2.9end of life · EOL 2025-04-18
    standard supportend of life
  • 2.8end of life · EOL 2024-12-31
    standard supportend of life
  • 2.7end of life · EOL 2024-05-29
    standard supportend of life
  • 2.6end of life · EOL 2023-08-02
    standard supportend of life
  • 2.5end of life · EOL 2022-09-20
    standard supportend of life
  • 2.4end of life · EOL 2022-04-25
    standard supportend of life
  • 2.3end of life · EOL 2021-05-10
    standard supportend of life
  • 2.2end of life · EOL 2021-01-01
    standard supportend of life
  • 2.1end of life · EOL 2020-09-24
    standard supportend of life
  • 2.0end of life · EOL 2020-06-26
    standard supportend of life
  • 1.0end of life · EOL 2020-05-04
    standard supportend of life
  • 0.11end of life · EOL 2019-04-24
    standard supportend of life
  • 0.10end of life · EOL 2018-05-10
    standard supportend of life
  • 0.9end of life · EOL 2017-04-20
    standard supportend of life

Showing 16 of 20 lines with lifecycle periods. See the directory below for the full list.

Known exploited vulnerabilities

CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.

  • CVE-2023-44487Known exploited

    HTTP/2 Rapid Reset Attack Vulnerability

    CISA KEV:
    listed · added 2023-10-10 · due 2023-10-31
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-400
    Affected:
    >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<=1.57.0-NA; >=1.19.0,<1.19.1; <=2.427; >=12.0.0,<12.0.2; <4.2.2; <3.4.2; <1.26.0; >=2.14.1,<=2.14.1; <4.1.100; <1.57.0; >=1.9.5,<=1.25.2; <1.21.4.3; <2.5.0; >=1.5,<1.1; >=3.0.0-beta3,<2.10.5; >=20.0.0,<20.8.1; <10.5.3; <9.4.0; >=11.0.0-milestone9,<=11.0.0-milestone9; >=9.0.0,<9.2.3; <1.28.0; <2023-10-08; <2.7.5; >=7.0.0,<7.0.12; >=1.27.0,<=1.27.0; <2023.10.16.00; >=1.21.0,<1.21.3; <0.17.0; >=4.0,<=4.0; >=1.57.0-NA,<1.58.3
    Fixed in:
    1.58.3, 1.19.1, 12.0.2, 4.2.2, 3.4.2, 1.26.0, 4.1.100, 1.57.0, 1.21.4.3, 2.5.0, 1.1, 2.10.5, 20.8.1, 10.5.3, 9.4.0, 9.2.3, 1.28.0, 2023-10-08, 2.7.5, 7.0.12, 2023.10.16.00, 1.21.3, 0.17.0
    Source:
    CISA KEV · Advisory

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

Known vulnerabilities
12
Known exploited
1
Highest CVSS
7.5
  • CVE-2023-44487Known exploited

    HTTP/2 Rapid Reset Attack Vulnerability

    CISA KEV:
    listed · added 2023-10-10 · due 2023-10-31
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-400
    Affected:
    >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<=1.57.0-NA; >=1.19.0,<1.19.1; <=2.427; >=12.0.0,<12.0.2; <4.2.2; <3.4.2; <1.26.0; >=2.14.1,<=2.14.1; <4.1.100; <1.57.0; >=1.9.5,<=1.25.2; <1.21.4.3; <2.5.0; >=1.5,<1.1; >=3.0.0-beta3,<2.10.5; >=20.0.0,<20.8.1; <10.5.3; <9.4.0; >=11.0.0-milestone9,<=11.0.0-milestone9; >=9.0.0,<9.2.3; <1.28.0; <2023-10-08; <2.7.5; >=7.0.0,<7.0.12; >=1.27.0,<=1.27.0; <2023.10.16.00; >=1.21.0,<1.21.3; <0.17.0; >=4.0,<=4.0; >=1.57.0-NA,<1.58.3
    Fixed in:
    1.58.3, 1.19.1, 12.0.2, 4.2.2, 3.4.2, 1.26.0, 4.1.100, 1.57.0, 1.21.4.3, 2.5.0, 1.1, 2.10.5, 20.8.1, 10.5.3, 9.4.0, 9.2.3, 1.28.0, 2023-10-08, 2.7.5, 7.0.12, 2023.10.16.00, 1.21.3, 0.17.0
    Source:
    CISA KEV · Advisory
  • CVE-2026-45135

    Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files

    Affected:
    >=2.7.0,<2.11.3
    Fixed in:
    2.11.3
    Source:
    OSV source · Advisory
  • CVE-2026-45692

    Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization

    Affected:
    >=2.4.0,<2.11.3
    Fixed in:
    2.11.3
    Source:
    OSV source · Advisory
  • CVE-2026-52845

    Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

    Affected:
    <2.11.4
    Fixed in:
    2.11.4
    Source:
    OSV source · Advisory
  • CVE-2026-52844

    Caddy: Windows `file_server` path authorization bypass via encoded backslash

    Affected:
    <2.11.4
    Fixed in:
    2.11.4
    Source:
    OSV source · Advisory
  • CVE-2026-52846

    Caddy: stripHTML template function bypass

    Affected:
    <2.11.4
    Fixed in:
    2.11.4
    Source:
    OSV source · Advisory
  • CVE-2026-30851

    Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation

    Affected:
    >=2.10.0,<2.11.2
    Fixed in:
    2.11.2
    Source:
    OSV source · Advisory
  • CVE-2026-30852

    Caddy: vars_regexp double-expands user input, leaking env vars and files

    Affected:
    >=2.7.5,<2.11.2
    Fixed in:
    2.11.2
    Source:
    OSV source · Advisory
  • CVE-2026-27590

    Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport

    Affected:
    <2.11.1
    Fixed in:
    2.11.1
    Source:
    OSV source · Advisory
  • CVE-2026-27589

    Caddy vulnerable to cross-origin config application via local admin API /load (caddy)

    Affected:
    <2.11.1
    Fixed in:
    2.11.1
    Source:
    OSV source · Advisory
  • CVE-2026-27588

    Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass

    Affected:
    >=2.10.2,<2.11.1
    Fixed in:
    2.11.1
    Source:
    OSV source · Advisory
  • CVE-2026-27587

    Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass

    Affected:
    >=2.10.2,<2.11.1
    Fixed in:
    2.11.1
    Source:
    OSV source · Advisory

Compare versions

Side-by-side view of the most relevant release lines.

2.112.10
Statusstandard supportend of life
Latest2.11.42.10.2
Released2026-06-032025-08-23
EOLNot officially published2026-02-23
Risklowhigh

Recent releases

Latest release date 2026-06-03 · 0 in last 30 days · 0 in last 90 days

Should I upgrade?

Current versions are supported

The preferred supported release line is Caddy 2.11 (standard support).

Open upgrade planner →

Upgrade planning

Plan upgrades from Caddy version lines that have newer supported options.

Compatibility

Evidence-backed Caddy compatibility results from declared requirements — open the Compatibility Explorer for the full matrix.

Open Compatibility Explorer →

Data coverage

Version lines
20
Concrete releases
87
Supported lines
1
EOL lines
19
Lifecycle coverage
20/20
EOL coverage
19/20
Provenance coverage
20/20

Data freshness

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Data last checked
2026-09-02
Latest source update
2026-09-02

Sources

First-party and other registered sources contributing release and lifecycle facts.

Version line directory

Complete navigation into detailed version-line pages.

Currently supported

Version lineStatusLatest releaseReleasedEOL
2.11
standard supportlow
2.11.42026-06-03Not officially published

End of life

Version lineStatusLatest releaseReleasedEOL
2.10
end of lifehigh
2.10.22025-08-232026-02-23
2.9
end of lifehigh
2.9.12025-01-082025-04-18
2.8
end of lifehigh
2.8.42024-06-022024-12-31
2.7
end of lifehigh
2.7.62023-12-082024-05-29
2.6
end of lifehigh
2.6.42023-02-142023-08-02
2.5
end of lifehigh
2.5.22022-07-122022-09-20
2.4
end of lifehigh
2.4.62021-11-082022-04-25
2.3
end of lifehigh
2.3.02021-01-012021-05-10
2.2
end of lifehigh
2.2.12020-10-132021-01-01
2.1
end of lifehigh
2.1.12020-06-302020-09-24
2.0
end of lifehigh
2.0.02020-05-042020-06-26
1.0
end of lifehigh
1.0.42019-11-152020-05-04
0.11
end of lifehigh
0.11.52019-03-042019-04-24
0.10
end of lifehigh
0.10.142018-04-202018-05-10
0.9
end of lifehigh
0.9.52017-01-242017-04-20
0.8
end of lifehigh
0.8.32016-04-262016-07-19
0.7
end of lifehigh
0.7.62015-09-292015-12-04
0.6
end of lifehigh
0.6.02015-05-072015-05-25
0.5
end of lifehigh
0.5.12015-04-302015-05-07