CVE-2026-27588: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-27588 is a host-based route and authentication bypass vulnerability in the Caddy web server affecting versions 2.10.2 through 2.11.0. Caddy's MatchHost HTTP request matcher is documented as case-insensitive, but when configured with more than 100 host entries, an optimized binary-search fast path performs case-sensitive string comparisons, allowing an attacker to bypass host-based routing and any attached access controls simply by altering the casing of the Host header. The vulnerability was discovered by Asim Viladi Oglu Manizada using an AI-assisted pipeline, reported on February 23, 2026, and published by NVD on February 24, 2026. It carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-178 (Improper Handling of Case Sensitivity). In modules/caddyhttp/matchers.go, the MatchHost.MatchWithError function activates a "large list" fast path via binary search when the host list exceeds 100 entries (len(m) > 100). This fast path uses a case-sensitive equality check (m[pos] == reqHost) rather than strings.EqualFold, and the subsequent fallback loop short-circuits before reaching the case-insensitive comparison for configurations containing only exact hostnames (no wildcards or placeholders). The attack vector is purely network-based, requires no authentication or user interaction, and the only precondition is that the target Caddy instance must have more than 100 exact hostnames configured in a host matcher block. A public proof-of-concept bash script using curl with a mixed-case Host header (e.g., Host: H050.TEST) was included in the advisory and confirmed to bypass a 403 deny rule, returning a 200 response (GitHub Advisory, Caddy Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to bypass host-based routing rules and any access controls (e.g., basicauth, forward_auth, respond deny) attached to those routes. In multi-tenant deployments where Caddy fronts applications and enforces per-host authorization, an attacker can reach protected endpoints such as /admin without credentials by sending a request with a case-altered Host header. The upstream application typically treats the altered hostname as equivalent to the legitimate one, meaning the guard is bypassed at the Caddy layer while the backend still serves the protected resource, resulting in high confidentiality and integrity impact (GitHub Advisory).

Exploitability

A proof-of-concept exploit script is publicly available in the GitHub Security Advisory, demonstrating the bypass with a simple curl command. The CVSS v4.0 exploit maturity is rated "Proof of Concept." As of the time of disclosure, there is no evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042% (0.000420), placing it in the 20th percentile for exploitation probability within 30 days. No specific threat actor attribution has been reported (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Caddy server instances using tools like Shodan or Censys (search for Server: Caddy response headers). Confirm the version is between 2.10.2 and 2.11.0.
  2. Identify target routes: Probe the server to discover host-based routing rules. Attempt requests with known or guessed hostnames to identify which hosts are in the protected list (responses of 403 or redirects indicate a match).
  3. Confirm large host list: If the server returns 403 for a lowercase Host header (e.g., Host: h050.test), the host is in the protected list. The bypass only works if the list has more than 100 entries.
  4. Craft bypass request: Send an HTTP request to the protected endpoint with the Host header value altered to mixed or uppercase (e.g., Host: H050.TEST or Host: H050.Test):
    curl -v -H 'Host: H050.TEST' http://<target-ip>:<port>/admin
  5. Achieve bypass: The Caddy MatchHost fast path fails to match the case-altered hostname against the protected list, causing the request to fall through to the default (unprotected) handler, which serves the resource with a 200 OK response — bypassing basicauth, forward_auth, or deny rules (GitHub Advisory, Caddy Advisory).

Indicators of compromise

  • Network: HTTP requests to protected paths (e.g., /admin, /api) with Host headers containing mixed-case or uppercase characters that correspond to known lowercase hostnames in the Caddy configuration (e.g., H050.TEST instead of h050.test).
  • Logs: Caddy access logs (http.log.access) showing requests to sensitive URIs returning HTTP 200 where the host field contains uppercase or mixed-case values that should have been denied (403); compare against expected deny rules. Example log pattern:
    {"host":"H050.TEST","uri":"/admin","status":200}
  • Logs: Absence of expected 403 responses for requests to protected routes from external IPs, particularly where the Host header casing differs from the configured lowercase entries.
  • Behavioral: Unexpected access to administrative or tenant-specific endpoints from IP addresses not associated with legitimate administrative users, especially when the upstream application logs show access that Caddy should have blocked (GitHub Advisory).

Mitigation and workarounds

The fix is included in Caddy version 2.11.1, which normalizes hostnames to lowercase during MatchHost.Provision and normalizes the incoming reqHost before the large-list binary search, restoring case-insensitive behavior on the optimized path. Organizations running Caddy 2.10.2 through 2.11.0 with more than 100 host entries in any host matcher block should upgrade to v2.11.1 immediately. No configuration-based workaround is available for the vulnerable versions; the only remediation is upgrading. After upgrading, administrators should review access logs for signs of prior exploitation using mixed-case Host headers (Caddy Release, GitHub Advisory).

Community reactions

The Caddy maintainer (mholt) published the fix as part of the v2.11.1 release, which bundled six security patches simultaneously, indicating a coordinated security release cycle (Caddy Release). The vulnerability was noted by security aggregators including The Hacker Wire and discussed on Bluesky shortly after disclosure. Red Hat tracked the issue via Bugzilla (Bug 2442408) and assigned it high severity, and SUSE issued a govulncheck advisory. The reporter disclosed use of an AI agent pipeline for discovery, which drew some community interest regarding AI-assisted vulnerability research (Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

caddy

Affected

sid

caddy: 2.11.2-1

Fixed

trixie

caddy: 2.6.2-12+deb13u1

Fixed

Ubuntu

Unknown

devel

caddy

Unknown

noble

caddy

Unknown

noble (esm-apps)

caddy

Unknown

resolute

caddy

Unknown

resolute (esm-apps)

caddy

Unknown

Alpine

Fixed

edge

caddy: 2.11.1-r0

Fixed

v3.23

caddy: 2.11.2-r0

Fixed

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management