Junglewise Threat Intelligence

CVE-2026-12357: Heimdall Data Database Proxy CRLF injection in generateFileContent

CVE-2026-12357 · Severity: high · CVSS 7.2 · Published 2026-07-29

Executive brief

Heimdall Data Database Proxy, a solution used to manage and optimize database traffic, contains a vulnerability that could allow an authorized user to take full control of the system. By exploiting a flaw in how the software handles specific file generation requests, an attacker can execute malicious commands with the highest level of system privileges (root). This could lead to a total compromise of the database proxy, including the theft of sensitive data or the disruption of all database operations.

Technical details

A remote code execution vulnerability exists in Heimdall Data Database Proxy within the generateFileContent function. The root cause is the improper neutralization of Carriage Return Line Feed (CRLF) sequences, which allows an attacker to inject malicious content into generated files. While exploitation requires authentication with high privileges (PR:H), a successful attack enables arbitrary code execution in the context of the root user. The vulnerability was addressed in release build 25.03.01.24.

Affected products

  • Heimdall Data Database Proxy 25.03.01.21

Timeline

  • 2026-02-12: disclosed: Vulnerability reported to vendor
  • 2026-07-23: patched: Fixed in release build 25.03.01.24
  • 2026-07-23: advisory: Coordinated public release of advisory ZDI-26-447

References

Related threats