CVE-2026-42274Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to RFC 3986, Section 6.2.2.3. This discrepancy can result in heimdall authorizing a request for one path (e.g., /user/../admin, or URL-encoded variants such as /user/%2e%2e/admin or /user/%2e%2e%2fadmin. The latter would require the allow_encoded_slashes option to be set to on or no_decode.) while the downstream ultimately processes a different, normalized path (/admin). This issue has been patched in version 0.17.14.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-35CWE-436

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-09: 2Patch / Workaround · 2026-05-09: 2Technical Details · 2026-05-09: 105-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42274 Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normali… https://www.cve.org/CVERecord?id=CVE-2026-42274 ----- Traducción: CVE-2026-42274 Hei… http://infoflow.cloud`

    Post summary

    CVE-2026-42274 affects Heimdall's rule matching on raw input before v0.17.14; the vulnerability is addressed in that release.

    0000029
    76 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42274 Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normali… https://www.cve.org/CVERecord?id=CVE-2026-42274

    Post summary

    The post links to the CVE record for CVE-2026-42274 and notes that version 0.17.14 fixes the issue, but offers no detailed technical data or exploitation evidence.

    00000175
    57.5K followersView on X

Explore more