Back

HIGH

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

Published Jun 23, 2026

Description

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identity header before copying the trusted value from the auth gateway. But when the request later goes through php_fastcgi, Caddy normalizes HTTP headers into CGI variables by replacing - with _. This lets a client send an underscore alias that survives the forward_auth delete step but becomes the same PHP/FastCGI variable. Result: a remote client can inject or sometimes override identity/group headers trusted by PHP/FastCGI applications behind Caddy. This vulnerability is fixed in 2.11.4.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jun 23, 2026
Updated Jul 15, 2026
Reserved Jun 8, 2026

CISA Vulnrichment

Updated Jun 24, 2026

NVD

Status Modified
Modified Jul 15, 2026

Red Hat

Severity Important
Public date Jun 23, 2026
Bugzilla 2491907

ENISA EUVD

Assigner GitHub_M
Published Jun 23, 2026
Updated Jul 15, 2026