CVE-2026-27588Disclosure(caddyserver / caddy)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch caddyserver caddy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host list (>100 entries) it becomes case-sensitive due to an optimized matching path. An attacker can bypass host-based routing and any access controls attached to that route by changing the casing of the `Host` header. Version 2.11.1 contains a fix for the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • caddy

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
caddy

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-24: 1Mentions · 2026-02-25: 3Mentions · 2026-10-05: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 302-2402-2510-05
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-241
Disclosure1
2026-02-253
Disclosure2Patch1
Full discourse5 posts
  • Jackon J Ray@JacksonJRay

    Caddy is a top trending GitHub project for the day, an extensible multi-platform HTTP/1-2-3 server written in Go that serves TLS by default with no external dependencies. It matters now because CVE-2026-27588 is an authorization bypass vulnerability in the Caddy web server platform: the HTTP host request matcher is documented as case-insensitive but becomes case-sensitive when configured with a host list of more than 100 entries due to an optimized matching path. A short Caddyfile can put a site or API in production with HTTPS and a reverse proxy, and the project itself says it is production-ready after trillions of requests with no external dependencies. https://github.com/caddyserver/caddy

    0000043
    22 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27588 - Critical Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a... https://www.thehackerwire.com/vulnerability/CVE-2026-27588/ https://t.co/k7EwNRJgqh

    Post summary

    A critical vulnerability in Caddy’s HTTP host matcher, affecting versions prior to 2.11.1, has been disclosed, with details available via the provided link.

    0000054
    116 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-27588 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but w… https://www.cve.org/CVERecord?id=CVE-2026-27588

    Post summary

    CVE-2026-27588 impacts Caddy’s HTTP host matcher; the issue is addressed in version 2.11.1.

    00000142
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27588: Case Sensitive Chaos: Bypassing Caddy Authentication with a Shift Key A logic error in Caddy's HTTP host matcher allows attackers to bypass routing rules and associated security middleware (like authentication) by simply changing the c... https://cvereports.com/reports/CVE-2026-27588

    Post summary

    The post discloses a logic error in Caddy’s host matcher that lets attackers bypass authentication by altering the host header, but it does not provide a PoC, exploit code, or patch information.

    0000038
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27588 Host Header Case Sensitivity Bypass in Caddy Web Server Before 2.11.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27588

    Post summary

    A case sensitivity bypass in Caddy Web Server before 2.11.1 is disclosed as CVE-2026-27588, with no PoC, exploit, or patch details provided.

    0000043
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcaddyservercaddy---

Explore more