CVE-2026-42272Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (%2f) is not recognized and therefore not processed as expected when allow_encoded_slashes is set to off (the default setting). This discrepancy can lead to differences in how request paths are interpreted by heimdall and upstream components, which may result in authorization bypass. This issue has been patched in version 0.17.14.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178CWE-436

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-09: 2Patch / Workaround · 2026-05-09: 1Technical Details · 2026-05-09: 105-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-42272 Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-se… https://www.cve.org/CVERecord?id=CVE-2026-42272

    Post summary

    A new vulnerability (CVE‑2026‑42272) in Heimdall affects URL‑encoded slash handling; a fix is available in version 0.17.14.

    00010194
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42272 Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-se… https://www.cve.org/CVERecord?id=CVE-2026-42272 ----- Traducción: CVE-2026-42272 Hei… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-42272, noting an issue with URL‑encoded slashes in Heimdall before version 0.17.14, but provides no evidence of exploitation, patching, or detailed technical information.

    0000023
    76 followersView on X

Explore more