
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27588 is a host-based route and authentication bypass vulnerability in the Caddy web server affecting versions 2.10.2 through 2.11.0. Caddy's MatchHost HTTP request matcher is documented as case-insensitive, but when configured with more than 100 host entries, an optimized binary-search fast path performs case-sensitive string comparisons, allowing an attacker to bypass host-based routing and any attached access controls simply by altering the casing of the Host header. The vulnerability was discovered by Asim Viladi Oglu Manizada using an AI-assisted pipeline, reported on February 23, 2026, and published by NVD on February 24, 2026. It carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-178 (Improper Handling of Case Sensitivity). In modules/caddyhttp/matchers.go, the MatchHost.MatchWithError function activates a "large list" fast path via binary search when the host list exceeds 100 entries (len(m) > 100). This fast path uses a case-sensitive equality check (m[pos] == reqHost) rather than strings.EqualFold, and the subsequent fallback loop short-circuits before reaching the case-insensitive comparison for configurations containing only exact hostnames (no wildcards or placeholders). The attack vector is purely network-based, requires no authentication or user interaction, and the only precondition is that the target Caddy instance must have more than 100 exact hostnames configured in a host matcher block. A public proof-of-concept bash script using curl with a mixed-case Host header (e.g., Host: H050.TEST) was included in the advisory and confirmed to bypass a 403 deny rule, returning a 200 response (GitHub Advisory, Caddy Advisory).
Successful exploitation allows an unauthenticated remote attacker to bypass host-based routing rules and any access controls (e.g., basicauth, forward_auth, respond deny) attached to those routes. In multi-tenant deployments where Caddy fronts applications and enforces per-host authorization, an attacker can reach protected endpoints such as /admin without credentials by sending a request with a case-altered Host header. The upstream application typically treats the altered hostname as equivalent to the legitimate one, meaning the guard is bypassed at the Caddy layer while the backend still serves the protected resource, resulting in high confidentiality and integrity impact (GitHub Advisory).
A proof-of-concept exploit script is publicly available in the GitHub Security Advisory, demonstrating the bypass with a simple curl command. The CVSS v4.0 exploit maturity is rated "Proof of Concept." As of the time of disclosure, there is no evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042% (0.000420), placing it in the 20th percentile for exploitation probability within 30 days. No specific threat actor attribution has been reported (GitHub Advisory, Feedly).
Server: Caddy response headers). Confirm the version is between 2.10.2 and 2.11.0.Host header (e.g., Host: h050.test), the host is in the protected list. The bypass only works if the list has more than 100 entries.Host header value altered to mixed or uppercase (e.g., Host: H050.TEST or Host: H050.Test):curl -v -H 'Host: H050.TEST' http://<target-ip>:<port>/adminMatchHost fast path fails to match the case-altered hostname against the protected list, causing the request to fall through to the default (unprotected) handler, which serves the resource with a 200 OK response — bypassing basicauth, forward_auth, or deny rules (GitHub Advisory, Caddy Advisory)./admin, /api) with Host headers containing mixed-case or uppercase characters that correspond to known lowercase hostnames in the Caddy configuration (e.g., H050.TEST instead of h050.test).http.log.access) showing requests to sensitive URIs returning HTTP 200 where the host field contains uppercase or mixed-case values that should have been denied (403); compare against expected deny rules. Example log pattern:{"host":"H050.TEST","uri":"/admin","status":200}Host header casing differs from the configured lowercase entries.The fix is included in Caddy version 2.11.1, which normalizes hostnames to lowercase during MatchHost.Provision and normalizes the incoming reqHost before the large-list binary search, restoring case-insensitive behavior on the optimized path. Organizations running Caddy 2.10.2 through 2.11.0 with more than 100 host entries in any host matcher block should upgrade to v2.11.1 immediately. No configuration-based workaround is available for the vulnerable versions; the only remediation is upgrading. After upgrading, administrators should review access logs for signs of prior exploitation using mixed-case Host headers (Caddy Release, GitHub Advisory).
The Caddy maintainer (mholt) published the fix as part of the v2.11.1 release, which bundled six security patches simultaneously, indicating a coordinated security release cycle (Caddy Release). The vulnerability was noted by security aggregators including The Hacker Wire and discussed on Bluesky shortly after disclosure. Red Hat tracked the issue via Bugzilla (Bug 2442408) and assigned it high severity, and SUSE issued a govulncheck advisory. The reporter disclosed use of an AI agent pipeline for discovery, which drew some community interest regarding AI-assisted vulnerability research (Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."