What caddyserver/caddy shipped
Written by FoxPlug from public releases; not affiliated with Caddy. An automatic summary of the public release, pull request and commit data of github.com/caddyserver/caddy. Caddy did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Week of September 21, 2026
What shipped
- reverse_proxy with HTTP/3 now respects tls_trust_pool instead of silently ignoring custom CAs and verifying against system roots. Pull request #8042
- map directive now allows the same input text for both literal and regexp rules, storing them in separate fields as intended. Pull request #8067
- caddyauth basic auth provider now only replaces known placeholders in usernames and passwords, preserving literal braces in credentials. Pull request #8017
- request_body set directive now only replaces known placeholders, preventing JSON bodies from being mangled or emptied. Pull request #8008
- caddyhttp now surfaces 413 status when request body placeholders exceed max_size limit instead of silently failing. Pull request #7969
- admin /load API now returns 400 Bad Request for invalid Caddyfiles with warnings instead of incorrectly returning 200 OK. Pull request #7267
- reverseproxy now flushes partial responses to clients instead of buffering them. Pull request #7849
- websocket header normalization moved later in processing to prevent rewriting by cloneRequest and other operations. Pull request #7921
- caddyhttp fixed off-by-one error in MaxSizeSubjectsListForLog that leaked one domain into output when maxToDisplay was 0. Pull request #7970
- fastcgi now explains why 411 responses occur for requests with unknown-length bodies like chunked or HTTP/2 without content-length. Pull request #7956
Why it matters
This week focused on correctness: fixing placeholder expansion that was silently corrupting user data, HTTP/3 TLS verification being ignored, and response handling issues. These bugs affected core features like reverse proxying, authentication, and request body processing.
Changelog entry
- reverse_proxy with HTTP/3 now respects tls_trust_pool configuration Pull request #8042
- map directive allows same input text for literal and regexp rules Pull request #8067
- caddyauth basic auth only replaces known placeholders in credentials Pull request #8017
- request_body set only replaces known placeholders, preserving JSON structure Pull request #8008
- request_body max_size limit now surfaces 413 status via placeholders Pull request #7969
- admin /load API returns 400 for invalid Caddyfiles with warnings Pull request #7267
- reverseproxy flushes partial responses to clients Pull request #7849
- websocket header normalization moved later to prevent unwanted rewrites Pull request #7921
- caddyhttp fixed MaxSizeSubjectsListForLog off-by-one error Pull request #7970
- caddyhttp randString sameCase dictionary corrected to exclude '0' Pull request #7972
- fastcgi explains 411 responses for unknown-length request bodies Pull request #7956
- Removed AI moderator workflow Pull request #8059
This week's fixes address placeholder expansion corrupting credentials and JSON bodies, HTTP/3 TLS verification being silently ignored, and partial response buffering. Several correctness improvements across auth, request handling, and reverse proxy.
This week's releases focus on data correctness and security. Fixes include placeholder expansion that was silently corrupting authentication credentials and JSON request bodies, HTTP/3 reverse proxies now respecting configured CA certificates instead of ignoring them, proper 413 status for oversized request bodies, and corrected response flushing behavior. These improvements affect core features like authentication, reverse proxying, and request body handling.