github.com/dadrus/heimdall
A cloud native Identity Aware Proxy and Access Control Decision service
Activity
- Latest release
- 2w ago
- Total releases
- 55
- Cadence
- ~22 days
- Last 12 months
- 20
Reach
- Stars
- 256
Details
- First release
- Jul 19, 2022
| Version | Released | |
|---|---|---|
v0.17.22
patch
|
v0.17.22
patch
Dependencies (83)
+ 75 more |
|
v0.17.21
patch
|
v0.17.21
patch
Dependencies (83)
+ 75 more |
|
v0.17.20
patch
|
v0.17.20
patch
Dependencies (83)
+ 75 more |
|
v0.17.19
patch
|
v0.17.19
patch
Dependencies (83)
+ 75 more |
|
v0.17.18
patch
|
v0.17.18
patch
Dependencies (83)
+ 75 more |
|
v0.17.17
patch
|
v0.17.17
patch
Dependencies (83)
+ 75 more |
|
v0.17.16
patch
2 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev |
v0.17.16
patch
Dependencies (83)
+ 75 more |
|
v0.17.15
patch
2 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev |
v0.17.15
patch
Dependencies (83)
+ 75 more |
|
v0.17.14
patch
2 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev |
v0.17.14
patch
Dependencies (84)
+ 76 more |
|
v0.17.13
patch
5 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev |
v0.17.13
patch
Dependencies (84)
+ 76 more |
|
v0.17.12
patch
5 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev |
v0.17.12
patch
Dependencies (84)
+ 76 more |
|
v0.17.11
patch
5 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev |
v0.17.11
patch
Dependencies (84)
+ 76 more |
|
v0.17.10
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.10
patch
Dependencies (84)
+ 76 more |
|
v0.17.9
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.9
patch
Dependencies (84)
+ 76 more |
|
v0.17.8
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.8
patch
Dependencies (85)
+ 77 more |
|
v0.17.7
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.7
patch
Dependencies (85)
+ 77 more |
|
v0.17.6
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.6
patch
Dependencies (85)
+ 77 more |
|
v0.17.5
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.5
patch
Dependencies (85)
+ 77 more |
|
v0.17.4
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.4
patch
Dependencies (85)
+ 77 more |
|
v0.17.3
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.3
patch
Dependencies (85)
+ 77 more |
|
v0.17.2
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.2
patch
Dependencies (85)
+ 77 more |
|
v0.17.1
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.1
patch
Dependencies (85)
+ 77 more |
|
v0.17.0
minor
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.17.0
minor
Dependencies (85)
+ 77 more |
|
v0.16.8
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.16.8
patch
Dependencies (85)
+ 77 more |
|
v0.16.7
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.16.7
patch
Dependencies (85)
+ 77 more |
|
v0.16.6
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.16.6
patch
Dependencies (85)
+ 77 more |
|
v0.16.2
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.16.2
patch
Dependencies (85)
+ 77 more |
|
v0.16.1
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.16.1
patch
Dependencies (85)
+ 77 more |
|
v0.16.0
minor
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.16.0
minor
Dependencies (85)
+ 77 more |
|
v0.15.10
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.15.10
patch
Dependencies (83)
+ 75 more |
|
v0.15.8
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.15.8
patch
Dependencies (83)
+ 75 more |
|
v0.15.6
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.15.6
patch
Dependencies (83)
+ 75 more |
|
v0.15.5
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.15.5
patch
Dependencies (83)
+ 75 more |
|
v0.15.4
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.15.4
patch
Dependencies (83)
+ 75 more |
|
v0.15.3
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.15.3
patch
Dependencies (83)
+ 75 more |
|
v0.15.2
patch
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.15.2
patch
Dependencies (83)
+ 75 more |
|
v0.15.1
initial
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.15.1
initial
Dependencies (83)
+ 75 more |
|
v0.14.4-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.14.4-alpha
pre
Dependencies (83)
+ 75 more |
|
v0.14.3-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.14.3-alpha
pre
Dependencies (83)
+ 75 more |
|
v0.14.2-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.14.2-alpha
pre
Dependencies (83)
+ 75 more |
|
v0.14.1-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.14.1-alpha
pre
Dependencies (83)
+ 75 more |
|
v0.14.0-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.14.0-alpha
pre
Dependencies (83)
+ 75 more |
|
v0.13.0-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.13.0-alpha
pre
Dependencies (79)
+ 71 more |
|
v0.12.0-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.12.0-alpha
pre
Dependencies (79)
+ 71 more |
|
v0.11.1-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.11.1-alpha
pre
Dependencies (66)
+ 58 more |
|
v0.11.0-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.11.0-alpha
pre
Dependencies (66)
+ 58 more |
|
v0.10.0-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.10.0-alpha
pre
Dependencies (66)
+ 58 more |
|
v0.9.0-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.9.0-alpha
pre
Dependencies (66)
+ 58 more |
|
v0.8.0-alpha
pre
6 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev
CVE-2026-32811
GO-2026-4742
GHSA-r8x2-fhmf-6mxp
Mar 23, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall Fixed in
0.17.11
References
Updated Mar 23, 2026 · Source: OSV.dev |
v0.8.0-alpha
pre
Dependencies (65)
+ 57 more |
|
v0.6.0-alpha
pre
5 CVEs
CVE-2026-57210
GO-2026-5075
GHSA-38x9-25wx-7fg2
Aug 11, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall When the trusted_proxies option is configured, heimdall extracts client IP addresses from the Forwarded and X-Forwarded-For headers and exposes them as Request.ClientIPAddresses to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 unknown values and obfuscated identifiers are accepted without further checks. In addition, the Forwarded header parser splits on commas and semicolons without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments treated as independent addresses. Request.ClientIPAddresses is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property. Additionally, in proxy mode, Request.ClientIPAddresses is used directly to construct the X-Forwarded-For and Forwarded headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. An attacker who can influence forwarding headers can inject arbitrary values into Request.ClientIPAddresses. In deployments where a rule references this property, this may allow an attacker to bypass the intended access control logic. In proxy mode, upstream services that trust this header may receive and act on attacker-controlled IP values. Fixed in
0.17.17
Updated Aug 11, 2026 · Source: OSV.dev
CVE-2026-42273
GO-2026-5200
GHSA-72h4-mxfc-jx37
Jun 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42272
GO-2026-5108
GHSA-43jv-5j4x-qv67
Jun 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42274
GO-2026-5097
GHSA-3q34-rx83-r6mq
Jun 25, 2026
Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall Fixed in
0.17.14
References
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-57209
GO-2026-5125
GHSA-4jgr-pg2m-m988
Jun 25, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall Fixed in
0.17.17
Updated Jul 20, 2026 · Source: OSV.dev |
v0.6.0-alpha
pre
Dependencies (51)
+ 43 more |