CVE-2026-32811Disclosure(dadrus / heimdall)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC decision API mode with versions 0.7.0-alpha through 0.17.10, wrong encoding of the query URL string allows rules with non-wildcard path expressions to be bypassed. Envoy splits the requested URL into parts, and sends the parts individually to Heimdall. Although query and path are present in the API, the query field is documented to be always empty and the URL query is included in the path field. The implementation uses go's url library to reconstruct the url which automatically encodes special characters in the path. As a consequence, a parameter like /mypath?foo=bar to Path is escaped into /mypath%3Ffoo=bar. Subsequently, a rule matching /mypath no longer matches and is bypassed. The issue can only lead to unintended access if Heimdall is configured with an "allow all" default rule. Since v0.16.0, Heimdall enforces secure defaults and refuses to start with such a configuration unless this enforcement is explicitly disabled, e.g. via --insecure-skip-secure-default-rule-enforcement or the broader --insecure flag. This issue has been fixed in version 0.17.11.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-116CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • heimdall

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
heimdall

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1Mentions · 2026-04-25: 1Technical Details · 2026-03-22: 1Technical Details · 2026-04-25: 103-2003-2204-25
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-201
General1
2026-03-221
Disclosure1
2026-04-251
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Heimdall (Identity Aware Proxy), Path Normalization Bypass, #CVE-2026-32811 (High) https://dailycve.com/heimdall-identity-aware-proxy-path-normalization-bypass-cve-2026-32811-high/

    Post summary

    An announcement of a Path Normalization Bypass vulnerability in Heimdall Identity Aware Proxy, identified as CVE-2026-32811 with high severity, with further details available via the linked article.

    0000060
    185 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A path corruption vulnerability (CVE-2026-32811) in `Heimdall` via `Envoy` gRPC could misinterpret request paths, potentially impacting authorization. Review configurations. #Heimdall #Envoy #APISecurity https://www.pulsepatch.io/posts/cve-2026-32811-heimdall-envoy-grpc-path-corruption

    Post summary

    The tweet discloses a path corruption vulnerability (CVE‑2026‑32811) in Heimdall via Envoy gRPC that may affect authorization, encouraging configuration review, but offers no PoC, exploit, or patch details.

    0000028
    2 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32811 Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC decision API mode with versions 0.7.0-alpha thr… https://www.cve.org/CVERecord?id=CVE-2026-32811

    Post summary

    The excerpt only references the CVE ID and the Heimdall service, without offering substantive information about the vulnerability, exploitation, or mitigations.

    0000082
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdadrusheimdall---

Explore more