Executive brief
Heimdall, an identity-aware proxy used to control access to web services, incorrectly handles uppercase letters in website addresses. An attacker can bypass security rules by simply changing the capitalization of a URL (e.g., using 'Admin.Example.Com' instead of 'admin.example.com'). This could allow unauthorized users to access restricted data or administrative functions if the system is configured with permissive default settings.
Technical details
Heimdall (prior to v0.17.14) implements case-sensitive host matching for its access rules. Because the HTTP Host header is technically case-insensitive, an attacker can provide a hostname with mixed casing (e.g., 'Admin.Example.Com') to avoid matching a specific security rule defined for a lowercase host. If the request fails to match the intended rule, Heimdall may fall back to a default rule; if that default rule is overly permissive (such as allowing anonymous access), the attacker achieves a policy bypass. This vulnerability is most critical in configurations where secure default rule enforcement has been explicitly disabled. The issue is resolved in version 0.17.14.
Affected products
- dadrus heimdall < 0.17.14
Timeline
- 2026-04-21: disclosed
- 2026-04-21: patched: Version 0.17.14 released
- 2026-04-25: advisory
- 2026-05-08: other: NVD published record
References
- https://github.com/dadrus/heimdall/security/advisories/GHSA-72h4-mxfc-jx37
- https://github.com/dadrus/heimdall/pull/3208
- https://github.com/dadrus/heimdall/commit/3d05e56a9e7ef0355f17482b4322054af4e85943
- https://github.com/dadrus/heimdall/releases/tag/v0.17.14
- https://api.github.com/repos/dadrus/heimdall/security-advisories/GHSA-72h4-mxfc-jx37