Executive brief
Caddy is a popular web server platform used to host websites and proxy traffic. A vulnerability in how it handles specific web requests allows attackers to trick the server into executing malicious code hidden in uploaded files or storage. This could lead to a full system takeover if an attacker is able to upload a file to the server, even if that file does not have a standard script extension like .php.
Technical details
A vulnerability exists in Caddy's FastCGI transport module due to improper handling of Unicode characters in the splitPos() function. The root cause is the misuse of the golang.org/x/text/search library with IgnoreCase, which performs complex Unicode equivalence matching that allows non-ASCII characters (like bold or script-style letters) to be interpreted as standard ASCII extensions (e.g., '.php'). Additionally, a logic error in the loop control flow can cause the server to incorrectly validate a file as a script if a non-ASCII byte is encountered. An unauthenticated remote attacker can exploit this by crafting a URL with specific Unicode sequences to bypass extension checks. If the attacker can also upload or place files on the server, this leads to Remote Code Execution (RCE) via the FastCGI upstream. The issue is resolved in version 2.11.3 by removing the unsafe Unicode fallback.
Affected products
- Caddyserver Caddy >= 2.7.0, < 2.11.3
Timeline
- 2026-05-13: advisory: GitHub advisory published by maintainers
- 2026-06-23: disclosed: CVE published to NVD
- 2026-06-23: patched: Fix confirmed in version 2.11.3