CVE-2026-27588
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host list (>100 entries) it becomes case-sensitive due to an optimized matching path. An attacker can bypass host-based routing and any access controls attached to that route by changing the casing of the `Host` header. Version 2.11.1 contains a fix for the issue.
- Affected products
- Caddy
- Caddyserver Caddy
- < 2.11.1
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.4% (30th percentile)
- Weakness
- CWE-178
- NVD status
- Analyzed
- Published
- 2026-02-24
CVE-2026-27588 at NVD
No indexed exploits for CVE-2026-27588 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-27588 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.