<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 22:53:09 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-309291</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-309291</link>
      <description>EUVD-2026-309291</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-309291</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42272</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42272</link>
      <description>&lt;p&gt;Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (%2f) is not recognized and therefore not processed as expected when allow_encoded_slashes is set to off (the default setting). This discrepancy can lead to differences in how request paths are interpreted by heimdall and upstream components, which may result in authorization bypass. This issue has been patched in version 0.17.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (%2f) is not recognized and therefore not processed as expected when allow_encoded_slashes is set to off (the default setting). This discrepancy can lead to differences in how request paths are interpreted by heimdall and upstream components, which may result in authorization bypass. This issue has been patched in version 0.17.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42272</guid>
    </item>
    <item>
      <title>GHSA-43jv-5j4x-qv67 — Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-43jv-5j4x-qv67</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/dadrus/heimdall&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Heimdall handles URL-encoded slashes (`%2F`) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (`%2f`) is not recognized and therefore not processed as expected when `allow_encoded_slashes` is set to `off` (the default setting).&lt;/p&gt;
&lt;p&gt;This discrepancy can lead to differences in how request paths are interpreted by heimdall and upstream components, which may result in authorization bypass.&lt;/p&gt;
&lt;p&gt;**Note:** The issue can only lead to unintended access if heimdall is configured with an &amp;#34;allow all&amp;#34; default rule. Since v0.16.0, heimdall enforces secure defaults and refuses to start with such a configuration unless this enforcement is explicitly disabled (e.g. via `--insecure-skip-secure-default-rule-enforcement` or the broader `--insecure` flag).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Consider the following rule configuration:&lt;/p&gt;
&lt;p&gt;```yaml
id: rule-1
match:
  routes:
    - path: /admin/**
execute: # configured to require authentication and authorization
  # ...
```&lt;/p&gt;
&lt;p&gt;If an adversary sends a request such as `/admin%2fsecret`, neither is the above rule matched, nor is the request rejected (as would be expected when `allow_encoded_slashes` is set to `off`). Instead, the default rule (if configured) will be executed.&lt;/p&gt;
&lt;p&gt;If the configured default rule is overly permissive (e.g. allowing anonymous access), and the upstream service interprets `%2f` as a path separator, the request may ultimately be processed as `/admin/secret`.&lt;/p&gt;
&lt;p&gt;This results i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/dadrus/heimdall&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Heimdall handles URL-encoded slashes (`%2F`) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (`%2f`) is not recognized and therefore not processed as expected when `allow_encoded_slashes` is set to `off` (the default setting).&lt;/p&gt;
&lt;p&gt;This discrepancy can lead to differences in how request paths are interpreted by heimdall and upstream components, which may result in authorization bypass.&lt;/p&gt;
&lt;p&gt;**Note:** The issue can only lead to unintended access if heimdall is configured with an &amp;#34;allow all&amp;#34; default rule. Since v0.16.0, heimdall enforces secure defaults and refuses to start with such a configuration unless this enforcement is explicitly disabled (e.g. via `--insecure-skip-secure-default-rule-enforcement` or the broader `--insecure` flag).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Consider the following rule configuration:&lt;/p&gt;
&lt;p&gt;```yaml
id: rule-1
match:
  routes:
    - path: /admin/**
execute: # configured to require authentication and authorization
  # ...
```&lt;/p&gt;
&lt;p&gt;If an adversary sends a request such as `/admin%2fsecret`, neither is the above rule matched, nor is the request rejected (as would be expected when `allow_encoded_slashes` is set to `off`). Instead, the default rule (if configured) will be executed.&lt;/p&gt;
&lt;p&gt;If the configured default rule is overly permissive (e.g. allowing anonymous access), and the upstream service interprets `%2f` as a path separator, the request may ultimately be processed as `/admin/secret`.&lt;/p&gt;
&lt;p&gt;This results i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-43jv-5j4x-qv67</guid>
    </item>
  </channel>
</rss>
