<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:38:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-310027</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310027</link>
      <description>EUVD-2026-310027</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310027</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42274</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42274</link>
      <description>&lt;p&gt;Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to RFC 3986, Section 6.2.2.3. This discrepancy can result in heimdall authorizing a request for one path (e.g., /user/../admin, or URL-encoded variants such as /user/%2e%2e/admin or /user/%2e%2e%2fadmin. The latter would require the allow_encoded_slashes option to be set to on or no_decode.) while the downstream ultimately processes a different, normalized path (/admin). This issue has been patched in version 0.17.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to RFC 3986, Section 6.2.2.3. This discrepancy can result in heimdall authorizing a request for one path (e.g., /user/../admin, or URL-encoded variants such as /user/%2e%2e/admin or /user/%2e%2e%2fadmin. The latter would require the allow_encoded_slashes option to be set to on or no_decode.) while the downstream ultimately processes a different, normalized path (/admin). This issue has been patched in version 0.17.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42274</guid>
    </item>
    <item>
      <title>GHSA-3q34-rx83-r6mq — Heimdall has an authorization bypass via path normalization mismatch</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3q34-rx83-r6mq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/dadrus/heimdall&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to [RFC 3986, Section 6.2.2.3](https://www.rfc-editor.org/rfc/rfc3986#section-6.2.2.3). This discrepancy can result in heimdall authorizing a request for one path (e.g., `/user/../admin`, or URL-encoded variants such as `/user/%2e%2e/admin` or `/user/%2e%2e%2fadmin`. The latter would require the `allow_encoded_slashes` option to be set to `on` or `no_decode`.) while the downstream ultimately processes a different, normalized path (`/admin`).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;This vulnerability can be exploited by an adversary if rule matching is performed using free (named or unnamed) wildcards without further constraints, as shown in the example snippets below.&lt;/p&gt;
&lt;p&gt;```yaml
id: rule-1
match:
  routes:
    - path: /user/**
execute: # configured to require authentication and authorization
  # ...
```&lt;/p&gt;
&lt;p&gt;```yaml
id: rule-2
match:
  routes:
    - path: /public/**
execute: # configured to allow anonymous access
  # ...
```&lt;/p&gt;
&lt;p&gt;If an adversary sends a request to `/public/../user/whatever`, rule-2 will be matched and executed. The downstream service may, however, normalize the request path and interpret it as `/user/whatever`.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Bypass of access control policies enforced by heimdall may lead to the following consequences:&lt;/p&gt;
&lt;p&gt;* Access to or modification of data that should be restricted
* Invocation of functionality that is expected to require authenti…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/dadrus/heimdall&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to [RFC 3986, Section 6.2.2.3](https://www.rfc-editor.org/rfc/rfc3986#section-6.2.2.3). This discrepancy can result in heimdall authorizing a request for one path (e.g., `/user/../admin`, or URL-encoded variants such as `/user/%2e%2e/admin` or `/user/%2e%2e%2fadmin`. The latter would require the `allow_encoded_slashes` option to be set to `on` or `no_decode`.) while the downstream ultimately processes a different, normalized path (`/admin`).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;This vulnerability can be exploited by an adversary if rule matching is performed using free (named or unnamed) wildcards without further constraints, as shown in the example snippets below.&lt;/p&gt;
&lt;p&gt;```yaml
id: rule-1
match:
  routes:
    - path: /user/**
execute: # configured to require authentication and authorization
  # ...
```&lt;/p&gt;
&lt;p&gt;```yaml
id: rule-2
match:
  routes:
    - path: /public/**
execute: # configured to allow anonymous access
  # ...
```&lt;/p&gt;
&lt;p&gt;If an adversary sends a request to `/public/../user/whatever`, rule-2 will be matched and executed. The downstream service may, however, normalize the request path and interpret it as `/user/whatever`.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Bypass of access control policies enforced by heimdall may lead to the following consequences:&lt;/p&gt;
&lt;p&gt;* Access to or modification of data that should be restricted
* Invocation of functionality that is expected to require authenti…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3q34-rx83-r6mq</guid>
    </item>
  </channel>
</rss>
