Improper Handling of Case Sensitivity Affecting github.com/caddyserver/caddy/v2/modules/caddyhttp/reverseproxy/fastcgi package, versions >=2.7.0 <2.11.3


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.68% (50th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMCADDYSERVERCADDYV2MODULESCADDYHTTPREVERSEPROXYFASTCGI-17706416
  • published30 Jun 2026
  • disclosed18 May 2026
  • creditUnknown

Introduced: 18 May 2026

CVE-2026-45135  (opens in a new tab)
CWE-176  (opens in a new tab)
CWE-178  (opens in a new tab)

How to fix?

Upgrade github.com/caddyserver/caddy/v2/modules/caddyhttp/reverseproxy/fastcgi to version 2.11.3 or higher.

Overview

Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity via the splitPos function. An attacker can execute arbitrary code by uploading a file with a specially crafted Unicode filename and accessing it through a crafted URL, causing the FastCGI handler to treat a non-script file as executable. This is only exploitable if the attacker can place files with arbitrary names on the server that are accessible via FastCGI.

CVSS Base Scores

version 4.0
version 3.1