Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
This flaw was introduced in github.com/smallstep/certificates 0.24.0, and patched in version 0.30.0. * Caddy in EPEL 8 and 9 bundles version 0.23.2, and thus is not affected. * Caddy in EPEL 10 bundles version 0.28.4, and thus is affected. * All active Fedora versions are affected, but I've cloned this bug to address it there.
FEDORA-EPEL-2026-6f59aff531 (caddy-2.10.2-9.el10_3) has been submitted as an update to Fedora EPEL 10.3. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-6f59aff531
FEDORA-EPEL-2026-7a183ed9a6 (caddy-2.10.2-9.el10_2) has been submitted as an update to Fedora EPEL 10.2. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-7a183ed9a6
FEDORA-EPEL-2026-6f59aff531 has been pushed to the Fedora EPEL 10.3 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-6f59aff531 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-EPEL-2026-7a183ed9a6 has been pushed to the Fedora EPEL 10.2 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-7a183ed9a6 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-EPEL-2026-6f59aff531 (caddy-2.10.2-9.el10_3) has been pushed to the Fedora EPEL 10.3 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-EPEL-2026-7a183ed9a6 (caddy-2.10.2-9.el10_2) has been pushed to the Fedora EPEL 10.2 stable repository. If problem still persists, please make note of it in this bug report.