caddy/modules/caddyhttp
JM Sanchez e2eee6a7fc
templates: Patch for GHSA-vcc4-2c75-vc9v (#7785)
* Patch GHSA-vcc4-2c75-vc9v in stripHTML

templates: fix funcStripHTML bypass via depth counter

The previous false-start approach allowed XSS bypass via inputs like <<>img src=x onerror=alert(1)> and failed on stacked angle brackets.

Replace the tagStart/inTag state machine with a depth counter that mirrors PHP strip_tags behaviour: each '<' increments depth, each '>' decrements it, and text is only emitted at depth zero. Quoted attribute values (both single and double) are tracked so '>' inside href values does not prematurely close a tag.

Signed-off-by: JM Sanchez <77505889+jmrcsnchz@users.noreply.github.com>

* Update tplcontext_test.go

Templates: expand TestStripHTML with attack path coverage

Signed-off-by: JM Sanchez <77505889+jmrcsnchz@users.noreply.github.com>

---------

Signed-off-by: JM Sanchez <77505889+jmrcsnchz@users.noreply.github.com>
2026-06-01 13:35:02 -06:00
..
caddyauth caddyauth: add candidate placeholders for rejected identities (#7698) 2026-05-20 13:51:54 +00:00
encode encode: prioritize zstd and br over gzip in content negotiation (#7772) 2026-05-29 05:26:19 +10:00
fileserver chore: clean up wording and typo fixes (#7745) 2026-05-20 16:36:30 +10:00
headers chore: Enable modernize linter (#7519) 2026-02-26 14:01:35 -07:00
intercept
logging logging: `log_append` Early option, Supports `{http.response.body}` (#7368) 2025-12-16 23:42:42 -05:00
map
proxyprotocol
push chore: Dumb `prealloc` lint fix (#7430) 2026-01-13 14:13:43 -05:00
requestbody
reverseproxy Merge commit from fork 2026-05-29 11:37:17 -06:00
rewrite rewrite: prevent placeholder re-expansion in injected query (#7761) 2026-05-26 16:51:18 -06:00
standard
templates templates: Patch for GHSA-vcc4-2c75-vc9v (#7785) 2026-06-01 13:35:02 -06:00
tracing metrics: Implement pushing via OLTP (#7664) 2026-04-25 06:52:08 -04:00
app.go tls: add alpn to managed HTTPS records (#7653) 2026-05-10 13:10:29 +10:00
autohttps.go tls: add alpn to managed HTTPS records (#7653) 2026-05-10 13:10:29 +10:00
autohttps_test.go tls: add alpn to managed HTTPS records (#7653) 2026-05-10 13:10:29 +10:00
caddyhttp.go
caddyhttp_test.go
celmatcher.go chore: clean up wording and typo fixes (#7745) 2026-05-20 16:36:30 +10:00
celmatcher_test.go chore: clean up wording and typo fixes (#7745) 2026-05-20 16:36:30 +10:00
errors.go use math/rand/v2 instead of math/rand (#7413) 2026-02-11 09:15:51 -07:00
http2listener.go chore: clean up wording and typo fixes (#7745) 2026-05-20 16:36:30 +10:00
httpredirectlistener.go chore: clean up wording and typo fixes (#7745) 2026-05-20 16:36:30 +10:00
invoke.go
ip_matchers.go
ip_range.go
logging.go
marshalers.go admin: Redact sensitive request headers in API logs (#7578) 2026-04-17 14:56:42 -06:00
matchers.go caddyhttp: normalize Windows backslashes in path matcher (#7763) 2026-05-21 11:28:40 -06:00
matchers_test.go caddyhttp: normalize Windows backslashes in path matcher (#7763) 2026-05-21 11:28:40 -06:00
metrics.go metrics: Implement pushing via OLTP (#7664) 2026-04-25 06:52:08 -04:00
metrics_test.go metrics: Implement pushing via OLTP (#7664) 2026-04-25 06:52:08 -04:00
replacer.go chore: Use atomics where appropriate (#7648) 2026-04-25 03:47:54 -04:00
replacer_test.go
responsematchers.go
responsematchers_test.go
responsewriter.go
responsewriter_test.go
routes.go chore: Fix golangci-lint 2.12.1 findings (#7690) 2026-05-07 03:40:26 -04:00
server.go Merge commit from fork 2026-05-29 11:37:17 -06:00
server_test.go Merge commit from fork 2026-05-29 11:37:17 -06:00
staticerror.go
staticresp.go chore: Add nolints to work around haywire linters (#7493) 2026-02-17 16:52:54 -07:00
staticresp_test.go
subroute.go
vars.go vars: Don't expand placeholders in values (#7629) 2026-04-10 09:37:43 -06:00
vars_test.go vars: Add matcher placeholder handling tests (#7640) 2026-04-10 16:27:52 -06:00