CVE-2026-27587 is a critical vulnerability affecting Caddy server versions prior to 2.11.1. It allows attackers to bypass path-based routing and access controls by manipulating the casing of percent-escaped sequences in request paths, due to an improper case-insensitivity implementation. With a CVSS score of 9.1 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and can lead to high confidentiality and integrity impacts. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.10.2, < 2.11.1CPE matchmatch criteria | cpe:2.3:a:caddyserver:caddy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.