highVulnerability

GHSA-38x9-25wx-7fg2

### Summary When the `trusted_proxies` option is configured, heimdall extracts client IP addresses from the `Forwarded` (`for=` parameter) and `X-Forwarded-For` headers and exposes them as `Request.ClientIPAddresses` to the rule pipeline. However, extracted values are not validated to be syntactically valid IP addresses. Arbitrary strings, malformed IP literals, and RFC 7239 `unknown` values and obfuscated identifiers are accepted without further checks. In addition, the `Forwarded` header parser splits on `,` and `;` without accounting for RFC 7239 quoted strings, which can cause a single quoted value to be parsed as multiple entries, with fragments — including trailing quote characters — treated as independent addresses. ### Impact `Request.ClientIPAddresses` is available to all pipeline mechanisms. Its contents can therefore influence rule evaluation in deployments where rules reference this property — for example, in a `CEL` authorizer that checks whether a request originates from a trusted IP range using the `networks()` function, or in a `Remote` authorizer that forwards the client IP as part of its payload to an external authorization system. Whether and how `Request.ClientIPAddresses` is used is entirely determined by the rule configuration. Additionally, in proxy mode, `Request.ClientIPAddresses` is used directly to construct the `X-Forwarded-For` and `Forwarded` headers forwarded to upstream services. Injected or malformed values are therefore propagated to upstream services unchanged. ### Attack Scenarios All scenarios require that `trusted_proxies` is configured. If this option is not set, heimdall ignores forwarding headers entirely, and this vulnerability is not exploitable. Scenarios A and C (see below) additionally require that rules reference `Request.ClientIPAddresses` in their pipeline. #### Scenario A – Manipulation of rule evaluation An attacker who can influence forwarding headers — either by connecting directly to heimdall or through

Properties

ghsa_id
GHSA-38x9-25wx-7fg2
summary
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
severity
high
cve_id
GHSA-38x9-25wx-7fg2
is_ghsa_only
true
ghsa_published
2026-06-18T14:24:37Z
source_url
https://github.com/advisories/GHSA-38x9-25wx-7fg2
ghsa_updated
2026-06-18T14:24:39Z

Related Entities (6)

HAS_WEAKNESS (3)

[Weakness]Improper Encoding or Escaping of Output
[Weakness]Improper Input Validation
[Weakness]Authentication Bypass by Spoofing

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/https://github.com/dadrus/heimdall

AFFECTS (1)

[Software]go/https://github.com/dadrus/heimdall

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-38x9-25wx-7fg2 — Ninja Signal Threat Intelligence | Ninja Signal