CVE-2026-27590: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-27590 is a Unicode case-folding path confusion vulnerability in Caddy's FastCGI transport that can lead to remote code execution (RCE) in certain deployment configurations. The flaw affects all versions of Caddy prior to 2.11.1 (Go module github.com/caddyserver/caddy/v2). It was initially reported to FrankenPHP (GHSA-g966-83w7-6w38) by researcher @AbdrrahimDahmani, then identified in Caddy by @dunglas; the advisory was published on February 23, 2026, and the CVE was assigned on February 24, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 8.9 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is an incorrect calculation of multi-byte string length (CWE-135) combined with improper input validation (CWE-20) and incorrect behavior order — validate before canonicalize (CWE-180). Caddy's splitPos() function in the FastCGI transport computes the split index for .php on a lowercased copy of the request path using strings.ToLower(), then applies that byte offset to the original path. Because strings.ToLower() can expand certain UTF-8 characters (e.g., Ⱥ (U+023A, 2 bytes) becomes ⱥ (U+2C65, 3 bytes)), the byte offset in the lowercased string does not correspond to the same position in the original string. This causes SCRIPT_NAME/SCRIPT_FILENAME and PATH_INFO to be computed incorrectly, shifting the split point so that a non-.php file (e.g., shell.php.txt) is treated as the PHP script to execute. A public PoC demonstrating the byte offset mismatch is included in the official advisory (Caddy Advisory, GitHub Advisory).

Impact

Successful exploitation allows an attacker to cause Caddy's FastCGI handler to execute an unintended on-disk file as a PHP script, bypassing the .php extension security boundary. In deployments where attackers can control file contents — such as applications with file upload features — this path confusion can result in full remote code execution, with high confidentiality, integrity, and availability impact on the vulnerable system. Even without file upload capabilities, the path confusion primitive itself is remotely triggerable via crafted URLs, potentially enabling information disclosure or other unintended behavior depending on server configuration (GitHub Advisory, Caddy Advisory).

Exploitability

A proof-of-concept (PoC) Go program demonstrating the byte offset mismatch is publicly available in the official Caddy security advisory, and the CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. No authentication or user interaction is required to trigger the path confusion primitive. There is no confirmed evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.19% (48th percentile), indicating a relatively low but non-negligible probability of exploitation in the near term (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Caddy instances running versions prior to 2.11.1 that use the FastCGI transport (i.e., configured to proxy PHP requests via php_fastcgi or equivalent). Use tools like Shodan or Censys to find exposed Caddy servers.
  2. Identify upload capability: Determine whether the target application allows file uploads to a location within or accessible from the document root (e.g., avatar uploads, file sharing features). This is required for RCE; path confusion alone is achievable without it.
  3. Upload malicious payload: Upload a file containing PHP code (e.g., a web shell) with a non-.php extension such as shell.php.txt to a path accessible by the Caddy server.
  4. Craft Unicode path: Construct a request URL that includes Unicode characters before the .php segment whose lowercased UTF-8 representation is longer in bytes (e.g., Ⱥ → ⱥ). Example path: /ȺȺȺȺshell.php.txt.php.
  5. Trigger path confusion: Send the crafted HTTP request to the Caddy server. The splitPos() function computes the split index on the lowercased path, but the expanded byte length shifts the offset so that when applied to the original path, SCRIPT_FILENAME resolves to shell.php.txt instead of a .php file.
  6. Achieve code execution: PHP-FPM executes the attacker-controlled shell.php.txt file as PHP, resulting in remote code execution under the web server's process privileges (Caddy Advisory, GitHub Advisory).

Indicators of compromise

  • Network: HTTP requests to Caddy-served PHP endpoints containing multi-byte Unicode characters (e.g., Ⱥ, ȺȺ) in the URL path, particularly paths ending in patterns like *.php.txt.php or similar double-extension constructs; unexpected outbound connections from the web server process.
  • Logs: Caddy access logs showing requests with encoded or raw multi-byte Unicode characters in the path (e.g., %C8%BA for Ⱥ) targeting FastCGI-proxied endpoints; PHP-FPM logs showing execution of non-.php files (e.g., .txt, .jpg) as PHP scripts.
  • File System: Presence of non-.php files in upload directories containing PHP code (e.g., <?php system($_GET['cmd']); ?>); newly created files in the document root or writable directories with unexpected extensions.
  • Process: Unusual child processes spawned by the PHP-FPM worker (e.g., sh, bash, curl, wget) following requests with Unicode-heavy paths.

Mitigation and workarounds

The primary remediation is to upgrade Caddy to version 2.11.1 or later, which fixes the splitPos() function to correctly handle Unicode byte length differences when computing the FastCGI path split index (Caddy Release). For deployments where an immediate upgrade is not possible, the following workarounds reduce risk: (1) store user-uploaded files outside the public document root so they cannot be resolved as SCRIPT_FILENAME; (2) implement WAF rules to reject requests containing specific multi-byte Unicode characters (e.g., Ⱥ, U+023A and similar expanding characters) in URL paths; (3) disable file upload features if not essential. Prioritize patching instances with PHP execution and file upload capabilities, as these are the highest-risk configurations (GitHub Advisory, FrankenPHP Advisory).

Community reactions

The vulnerability was originally discovered by researcher @AbdrrahimDahmani and reported to FrankenPHP, where it was assigned CVE-2026-24895 (GHSA-g966-83w7-6w38). Caddy maintainer @mholt subsequently identified that the same vulnerable code pattern had been copied into Caddy and published the Caddy advisory, with the patch ported from the FrankenPHP fix by @dunglas. The release of Caddy 2.11.1 bundled six security patches simultaneously, drawing community attention on platforms including Mastodon and Bluesky. Security aggregators including Vulners, CVEFeed, and CIRCL's vulnerability database indexed the CVE shortly after disclosure, and it was covered in a technical write-up by Infinit Security (Infinit Security, Caddy Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

caddy

Affected

sid

caddy: 2.11.2-1

Fixed

trixie

caddy: 2.6.2-12+deb13u1

Fixed

Ubuntu

Unknown

devel

caddy

Unknown

noble

caddy

Unknown

noble (esm-apps)

caddy

Unknown

resolute

caddy

Unknown

resolute (esm-apps)

caddy

Unknown

Alpine

Fixed

edge

caddy: 2.11.1-r0

Fixed

v3.23

caddy: 2.11.2-r0

Fixed

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management