Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-45135

Опубликовано: 23 июн. 2026
Источник: debian
EPSS Низкий

Описание

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or other configured split_path extension) file as a script. In any deployment where the attacker can place content into a file served via FastCGI (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This vulnerability is fixed in 2.11.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
caddyfixed2.11.4-1package
caddynot-affectedtrixiepackage
caddynot-affectedbookwormpackage

Примечания

  • https://github.com/caddyserver/caddy/security/advisories/GHSA-m675-2p33-xv9g

  • Fixed by: https://github.com/caddyserver/caddy/commit/fb324331f40782ac7a48d83f591c2bb7615d7eed (v2.11.3)

  • Introduced with: https://github.com/caddyserver/caddy/commit/7c28c0c07ac70a8960a166c7126150a408ba7464 (v2.11.0)

  • the vulnerable window is 2.11.0 to 2.11.2. 2.6.2's splitPos() is a plain

  • strings.Index() over a lower-cased copy; that separate flaw is CVE-2026-27590.

EPSS

Процентиль: 40%
0.00501
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 2 месяцев назад

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or other configured split_path extension) file as a script. In any deployment where the attacker can place content into a file served via FastCGI (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This vulnerability is fixed in 2.11.3.

CVSS3: 8.1
nvd
около 2 месяцев назад

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or other configured split_path extension) file as a script. In any deployment where the attacker can place content into a file served via FastCGI (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This vulnerability is fixed in 2.11.3.

CVSS3: 8.1
github
3 месяца назад

Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files

EPSS

Процентиль: 40%
0.00501
Низкий