CVE-2026-27589: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-27589 is a Cross-Site Request Forgery (CSRF) vulnerability in the Caddy web server's local admin API that allows attackers to replace the entire running configuration via cross-origin requests. It affects all versions of Caddy prior to 2.11.1, specifically the POST /load endpoint on the default admin listener (127.0.0.1:2019). The vulnerability was reported by researcher 1seal and published via GitHub Security Advisory on February 23, 2026, with NVD publication on February 24, 2026. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 6.9 (Medium) (Github Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper verification of the source of a communication channel (CWE-940) combined with a classic CSRF weakness (CWE-352). When the enforce_origin option is not configured in the admin endpoint, Caddy's adminLoad.handleLoad function in caddyconfig/load.go (line 73) does not validate the Origin header of incoming requests, allowing cross-origin POST /load requests to be accepted and processed. An attacker can craft a malicious web page that, when visited by a victim whose browser is running locally alongside a Caddy instance, silently issues a POST /load request with an attacker-controlled JSON configuration payload — effectively replacing the entire server configuration without authentication. A public proof-of-concept exploit (poc.zip) was released alongside the advisory, demonstrating the attack by moving the admin listener and altering HTTP response bodies (Github Advisory, Caddy Security Advisory).

Impact

Successful exploitation allows an attacker to replace the entire running Caddy configuration with an arbitrary attacker-supplied JSON config, resulting in a high integrity impact with no confidentiality or availability impact directly. Practically, this can enable an attacker to alter HTTP server routing and responses, move the admin listener to a new address (potentially exposing it externally), disable security controls such as TLS or authentication middleware, and redirect or manipulate traffic. The attack requires no authentication or elevated privileges, but does require a victim running Caddy locally to visit an attacker-controlled web page (Github Advisory, Caddy Security Advisory).

Exploitability

A public proof-of-concept exploit (poc.zip) is available and was published alongside the security advisory, demonstrating end-to-end exploitation including admin listener relocation and HTTP response tampering. The CVSS v4.0 exploit maturity is rated as PROOF_OF_CONCEPT. The EPSS score is approximately 0.019% (0.000190), indicating a low but non-zero probability of exploitation in the wild within 30 days. There is no current evidence of active in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a target system where Caddy is running with the admin API enabled (default: 127.0.0.1:2019) and enforce_origin is not configured. This is the default configuration for many Caddy deployments.
  2. Retrieve current configuration: From the attacker-controlled page or local context, fetch the current Caddy config via GET http://127.0.0.1:2019/config/ to understand the running configuration structure.
  3. Craft malicious payload: Modify the retrieved JSON configuration to include attacker-desired changes — for example, changing the admin listener address (cfg['admin']['listen'] = '127.0.0.1:2020') or altering HTTP route handlers to return attacker-controlled responses.
  4. Host malicious web page: Create a web page that, when loaded in a victim's browser, issues a cross-origin POST request to http://127.0.0.1:2019/load with the crafted JSON payload and a spoofed or arbitrary Origin header, using no-cors fetch mode or a form submission to bypass CORS preflight.
  5. Trigger victim interaction: Lure the victim (who is running Caddy locally) to visit the attacker-controlled page, causing the browser to send the cross-origin POST /load request.
  6. Verify impact: Confirm the configuration was applied by checking the new admin listener address or observing altered HTTP responses from the Caddy server (e.g., response body changed to pwned) (Caddy Security Advisory, Github Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to http://127.0.0.1:2019/load originating from a browser process with a non-localhost or unexpected Origin header; outbound connections from the Caddy admin port to new or unexpected addresses after a configuration change.
  • Logs: Caddy access logs showing POST /load requests with HTTP 200 responses from unexpected origins; log entries indicating the admin listener address changed unexpectedly.
  • Process/Configuration: Caddy admin API suddenly listening on a different address than the configured default (127.0.0.1:2019); HTTP server routes or responses changed without administrator action; unexpected modifications to the active Caddy configuration as observed via GET /config/.
  • File System: If the attacker's payload includes file-writing modules or reverse proxy redirects, look for new or modified Caddy configuration files or unexpected upstream proxy targets in the running config (Caddy Security Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Caddy to version 2.11.1 or later, which blocks cross-origin requests made with no-cors mode to state-changing admin endpoints by default (Caddy v2.11.1 Release). For deployments that cannot immediately upgrade, enable origin enforcement by adding enforce_origin to the admin endpoint configuration block in the Caddyfile, which restricts the admin API to only accept requests from trusted origins (Github Advisory). Additionally, consider restricting network access to the admin API port (2019) using firewall rules to prevent any unintended local or remote access.

Community reactions

The vulnerability was published by maintainer mholt via GitHub Security Advisory and included as one of several security patches in the Caddy 2.11.1 release, which also addressed five other CVEs (Caddy v2.11.1 Release). Red Hat tracked the issue via Bugzilla and assigned it medium severity (Red Hat Bugzilla). The Solus Linux community newsletter and INCIBE (Spain's national cybersecurity agency) also noted the vulnerability in their advisories. No significant controversy or widespread social media discussion has been observed beyond standard vulnerability tracking channels.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

caddy

Affected

sid

caddy: 2.11.2-1

Fixed

trixie

caddy: 2.6.2-12+deb13u1

Fixed

Ubuntu

Unknown

devel

caddy

Unknown

noble

caddy

Unknown

noble (esm-apps)

caddy

Unknown

resolute

caddy

Unknown

resolute (esm-apps)

caddy

Unknown

Alpine

Fixed

edge

caddy: 2.11.1-r0

Fixed

v3.23

caddy: 2.11.2-r0

Fixed

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management