Repository
caddyserver/caddy
Scanned on Jun 4, 2026
72
Risk score/ 100
High risk
Summary
Caddy's codebase contains critical use of cryptographically broken MD5 hashing and extensive ECDSA/ECC cryptography that is vulnerable to quantum attacks. While MD5 usage appears confined to FastCGI testing, the ECDSA implementations in ACME certificate management represent significant post-quantum cryptography risks that could compromise TLS certificate issuance once quantum computers become viable.
Critical
0
High
0
Medium
0
Low
0
Scan your own repository
Free. Results in ~90 seconds. CBOM + DORA/NIS2 PDF included.