v2.11.1
2026-03-04T20:24:46Z•592e58c718dbd0a4392ae8dcf41fb534fbe6ec230b3bad5aab8ab73d98d82a07
ECHSIGUSR1acmeacme-profilesautomatic-key-rotationcaddycaddyserverencrypted-clienthellohost-header-rewritelog_appendloggingpost-quantumrelease-notesreverse-proxysecurity-patchessensitive-data-loggingtime-rolling-logstlsv2.11.1x25519mlkem768
What happened
Caddy v2.11.1 published 2026-02-23 includes multiple bug fixes and “several security patches” (no CVE identifiers provided). Notable changes: Encrypted ClientHello (ECH) keys are rotated automatically; reverse proxy now rewrites the Host header to the upstream address when the upstream is HTTPS; log_append can record request and response bodies (potential sensitive-data exposure); SIGUSR1 can reload config in certain CLI scenarios; time-rolling log options added. Earlier 2.10.x/2.11.0 notes reference ECH support, post-quantum x25519mlkem768 key exchange, ACME profiles, global DNS provider, and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- caddyserver_caddy_releases
- Record identifier
- 592e58c718dbd0a4392ae8dcf41fb534fbe6ec230b3bad5aab8ab73d98d82a07
- Enrichment time
- 2026-03-04T20:24:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.