Improper Handling of Case Sensitivity Affecting github.com/caddyserver/caddy/v2/modules/caddyhttp package, versions <2.11.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.37% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMCADDYSERVERCADDYV2MODULESCADDYHTTP-15346651
  • published25 Feb 2026
  • disclosed24 Feb 2026
  • creditAsim Viladi Oglu Manizada

Introduced: 24 Feb 2026

CVE-2026-27588  (opens in a new tab)
CWE-178  (opens in a new tab)

How to fix?

Upgrade github.com/caddyserver/caddy/v2/modules/caddyhttp to version 2.11.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity in the host request matcher when the host list contains more than 100 entries. An attacker can gain unauthorized access to protected routes and sensitive endpoints by altering the case of the Host header in HTTP requests.

Note: This is only exploitable if the host matcher is configured with more than 100 exact hostnames and is used to enforce access controls.

CVSS Base Scores

version 4.0
version 3.1