CVE-2026-27587Disclosure(caddyserver / caddy)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains percent-escape sequences (`%xx`) it compares against the request's escaped path without lowercasing. An attacker can bypass path-based routing and any access controls attached to that route by changing the casing of the request path. Version 2.11.1 contains a fix for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • caddy

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-25)
  • 3 total mentions across 2 days

Affected systems

Products
caddy

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-24: 1Mentions · 2026-02-25: 2Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 202-2402-25
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-241
Disclosure1
2026-02-252
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27587 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but … https://www.cve.org/CVERecord?id=CVE-2026-27587

    Post summary

    The post announces a case‑sensitivity flaw in Caddy’s HTTP path matcher before v2.11.1, as documented in CVE‑2026‑27587.

    00000140
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27587: Caddy Shack: Bypassing ACLs with a Caps Lock Key A logic error in Caddy's HTTP path matching engine allows attackers to bypass access control lists (ACLs) by manipulating URL casing. When a configuration pattern involves percent-encode... https://cvereports.com/reports/CVE-2026-27587

    Post summary

    The report details a logic flaw in Caddy’s HTTP path matching that lets attackers bypass ACLs by altering URL casing and percent-encoding.

    0000043
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27587 Path Traversal Bypass in Caddy Web Server Prior to Version 2.11.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27587

    Post summary

    A path traversal bypass vulnerability (CVE-2026-27587) affecting Caddy Web Server versions prior to 2.11.1 has been disclosed, with no PoC, exploit, or patch details provided.

    0000059
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcaddyservercaddy---

Explore more