CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-f59h-q822-g45g: Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

highCVSS 8.1CVE-2026-52845
Summary forward_auth copy_headers deletes the exact client-supplied identity header before copying the trusted value from the auth gateway. But when the request later goes through php_fastcgi, Caddy normalizes HTTP headers into CGI variables by replacing - with _. This lets a client send an underscore alias that survives the forward_auth delete step but becomes the same PHP/FastCGI variable: Remote-Groups -> HTTP_REMOTE_GROUPS Remote_Groups -> HTTP_REMOTE_GROUPS Remote-User -> HTTP_REMOTE_USER Remote_User -> HTTP_REMOTE_USER Result: a remote client can inject or sometimes override identity/group headers trusted by PHP/FastCGI applications behind Caddy. Details forward_auth copy_headers intentionally removes client-controlled headers before setting values from the auth response: - modules/caddyhttp/reverseproxy/forwardauth/caddyfile.go:212 - modules/caddyhttp/reverseproxy/forwardauth/caddyfile.go:222 That delete is exact-field deletion through http.Header.Del(): - modules/caddyhttp/headers/headers.go:255 - modules/caddyhttp/headers/headers.go:281 So deleting Remote-Groups does not delete Remote_Groups. Later, FastCGI exports all request headers into CGI variables: - modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go:410 - modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go:414 - modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go:510 The normalizer replaces hyphens with underscores: strings.NewReplacer(" ", "_", "-", "_") So the trusted header and the attacker-controlled alias collide in the backend-visible CGI/PHP namespace. This is distinct from GHSA-7r4p-vjf4-gxv4. That issue allowed exact copied headers to survive. This report reproduces after the exact-header fix because the bypass uses a different HTTP field name that only becomes equivalent during Caddy's FastCGI export. PoC Run from the Caddy repository root with bash: set -euo pipefail tmpdir=$(mktemp -d /tmp/caddy-fastcgi-header-collision.XXXXXX) mkdir -p "$tmpdir/www" printf '<?php echo "ok

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high — CVSS 8.1
Published
2026-06-16
Last updated
2026-07-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-f59h-q822-g45g

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-52845coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories