Improper Handling of Case Sensitivity Affecting github.com/caddyserver/caddy/v2/modules/caddyhttp package, versions <2.11.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.37% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMCADDYSERVERCADDYV2MODULESCADDYHTTP-15346502
  • published25 Feb 2026
  • disclosed24 Feb 2026
  • creditAsim Viladi Oglu Manizada

Introduced: 24 Feb 2026

CVE-2026-27587  (opens in a new tab)
CWE-178  (opens in a new tab)

How to fix?

Upgrade github.com/caddyserver/caddy/v2/modules/caddyhttp to version 2.11.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity in the matchPatternWithEscapeSequence function when handling patterns containing percent-escape sequences. An attacker can gain unauthorized access to protected routes and sensitive endpoints by altering the case of characters in the request path, thereby bypassing intended access controls.

CVSS Base Scores

version 4.0
version 3.1