automatic HTTPS, which may result in the bypass of path- or host-based
access controls, the execution of an unintended file by a FastCGI
backend, the injection of identity headers trusted by applications
running behind Caddy, unauthorised reconfiguration of the server through
its admin API, or cross-site scripting.
The fix for CVE-2026-52845 follows upstream in dropping every request
header whose name contains an underscore, for all servers and without an
opt-out. Deployments which pass such headers through Caddy, for instance
X_Api_Key or gRPC custom metadata keys containing underscores, need to
switch to the hyphenated spelling.
https://security-tracker.debian.org/tracker/DSA-6429-1
SOCIAL SHARE CARD GENERATOR