HIGH8.2CVE-2026-32811Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall >= 0.7.0-alpha, < 0.17.11
HIGH8.2CVE-2026-32811Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall >= 0.7.0-alpha, < 0.17.11
—CVE-2026-57209Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall from 0, < 0.17.17
—CVE-2026-57209Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode in github.com/dadrus/heimdall from 0, < 0.17.17
—Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall
from 0, < 0.17.14
—Heimdall has an authorization bypass via path normalization mismatch in github.com/dadrus/heimdall
from 0, < 0.17.14
—Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall
from 0, < 0.17.14
—Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall
from 0, < 0.17.14
—Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall
from 0, < 0.17.14
—Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation in github.com/dadrus/heimdall
from 0, < 0.17.14