Junglewise Threat Intelligence

CVE-2026-42272: dadrus Heimdall authorization bypass via case-sensitive URL encoding

CVE-2026-42272 · Severity: high · CVSS 4 · Published 2026-04-25

Technologies: github.com/dadrus/heimdall (Go), Dadrus Heimdall. Vendors: Go, Dadrus.

Executive brief

Heimdall, an identity-aware proxy used to control access to web services, contains a flaw in how it processes web addresses. By using lowercase characters in certain parts of a web link, an attacker can trick the proxy into ignoring security rules while the backend service still processes the request. This can allow unauthorized users to access restricted data or administrative functions if the system is not configured with strict 'deny-by-default' rules.

Technical details

Heimdall improperly handles percent-encoded slashes by treating '%2F' and '%2f' differently, despite the specification requiring case-insensitivity. When 'allow_encoded_slashes' is set to 'off' (default), lowercase '%2f' is not recognized or rejected, causing the request to bypass specific path-based rules (e.g., /admin/**). If a permissive default rule is active, the request is forwarded to upstream services which may interpret '%2f' as a valid path separator, leading to an interpretation conflict and authorization bypass. This vulnerability is particularly impactful in configurations where secure defaults have been explicitly disabled. The issue is resolved in version 0.17.14.

Affected products

  • dadrus Heimdall < 0.17.14

Timeline

  • 2026-04-21: disclosed: Advisory published by maintainer
  • 2026-04-25: advisory: GHSA published
  • 2026-05-08: advisory: NVD published CVE-2026-42272
  • 2026-04-21: patched: Version 0.17.14 released

References

Related threats