Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0255

NIXPKGS-2026-0255
published on 15 Feb 2026
updated 3 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Caido has an insufficient patch for DNS rebind leading to RCE

Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the 8080 port, and shows Host/IP is not allowed to connect to Caido on all endpoints. But this is bypassable by injecting a X-Forwarded-Host: 127.0.0.1:8080 header. This vulnerability is fixed in 0.55.0.

Affected products

caido
  • ==< 0.55.0

Matching in nixpkgs

Package maintainers

Upstream advisory: https://github.com/caido/caido/security/advisories/GHSA-3q5q-p8vj-8783