
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27590 is a Unicode case-folding path confusion vulnerability in Caddy's FastCGI transport that can lead to remote code execution (RCE) in certain deployment configurations. The flaw affects all versions of Caddy prior to 2.11.1 (Go module github.com/caddyserver/caddy/v2). It was initially reported to FrankenPHP (GHSA-g966-83w7-6w38) by researcher @AbdrrahimDahmani, then identified in Caddy by @dunglas; the advisory was published on February 23, 2026, and the CVE was assigned on February 24, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 8.9 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an incorrect calculation of multi-byte string length (CWE-135) combined with improper input validation (CWE-20) and incorrect behavior order — validate before canonicalize (CWE-180). Caddy's splitPos() function in the FastCGI transport computes the split index for .php on a lowercased copy of the request path using strings.ToLower(), then applies that byte offset to the original path. Because strings.ToLower() can expand certain UTF-8 characters (e.g., Ⱥ (U+023A, 2 bytes) becomes ⱥ (U+2C65, 3 bytes)), the byte offset in the lowercased string does not correspond to the same position in the original string. This causes SCRIPT_NAME/SCRIPT_FILENAME and PATH_INFO to be computed incorrectly, shifting the split point so that a non-.php file (e.g., shell.php.txt) is treated as the PHP script to execute. A public PoC demonstrating the byte offset mismatch is included in the official advisory (Caddy Advisory, GitHub Advisory).
Successful exploitation allows an attacker to cause Caddy's FastCGI handler to execute an unintended on-disk file as a PHP script, bypassing the .php extension security boundary. In deployments where attackers can control file contents — such as applications with file upload features — this path confusion can result in full remote code execution, with high confidentiality, integrity, and availability impact on the vulnerable system. Even without file upload capabilities, the path confusion primitive itself is remotely triggerable via crafted URLs, potentially enabling information disclosure or other unintended behavior depending on server configuration (GitHub Advisory, Caddy Advisory).
A proof-of-concept (PoC) Go program demonstrating the byte offset mismatch is publicly available in the official Caddy security advisory, and the CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. No authentication or user interaction is required to trigger the path confusion primitive. There is no confirmed evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.19% (48th percentile), indicating a relatively low but non-negligible probability of exploitation in the near term (GitHub Advisory, Feedly).
php_fastcgi or equivalent). Use tools like Shodan or Censys to find exposed Caddy servers..php extension such as shell.php.txt to a path accessible by the Caddy server..php segment whose lowercased UTF-8 representation is longer in bytes (e.g., Ⱥ → ⱥ). Example path: /ȺȺȺȺshell.php.txt.php.splitPos() function computes the split index on the lowercased path, but the expanded byte length shifts the offset so that when applied to the original path, SCRIPT_FILENAME resolves to shell.php.txt instead of a .php file.shell.php.txt file as PHP, resulting in remote code execution under the web server's process privileges (Caddy Advisory, GitHub Advisory).Ⱥ, ȺȺ) in the URL path, particularly paths ending in patterns like *.php.txt.php or similar double-extension constructs; unexpected outbound connections from the web server process.%C8%BA for Ⱥ) targeting FastCGI-proxied endpoints; PHP-FPM logs showing execution of non-.php files (e.g., .txt, .jpg) as PHP scripts..php files in upload directories containing PHP code (e.g., <?php system($_GET['cmd']); ?>); newly created files in the document root or writable directories with unexpected extensions.sh, bash, curl, wget) following requests with Unicode-heavy paths.The primary remediation is to upgrade Caddy to version 2.11.1 or later, which fixes the splitPos() function to correctly handle Unicode byte length differences when computing the FastCGI path split index (Caddy Release). For deployments where an immediate upgrade is not possible, the following workarounds reduce risk: (1) store user-uploaded files outside the public document root so they cannot be resolved as SCRIPT_FILENAME; (2) implement WAF rules to reject requests containing specific multi-byte Unicode characters (e.g., Ⱥ, U+023A and similar expanding characters) in URL paths; (3) disable file upload features if not essential. Prioritize patching instances with PHP execution and file upload capabilities, as these are the highest-risk configurations (GitHub Advisory, FrankenPHP Advisory).
The vulnerability was originally discovered by researcher @AbdrrahimDahmani and reported to FrankenPHP, where it was assigned CVE-2026-24895 (GHSA-g966-83w7-6w38). Caddy maintainer @mholt subsequently identified that the same vulnerable code pattern had been copied into Caddy and published the Caddy advisory, with the patch ported from the FrankenPHP fix by @dunglas. The release of Caddy 2.11.1 bundled six security patches simultaneously, drawing community attention on platforms including Mastodon and Bluesky. Security aggregators including Vulners, CVEFeed, and CIRCL's vulnerability database indexed the CVE shortly after disclosure, and it was covered in a technical write-up by Infinit Security (Infinit Security, Caddy Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."