GHSA-43jv-5j4x-qv67
### Summary Heimdall handles URL-encoded slashes (`%2F`) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (`%2f`) is not recognized and therefore not processed as expected when `allow_encoded_slashes` is set to `off` (the default setting). This discrepancy can lead to differences in how request paths are interpreted by heimdall and upstream components, which may result in authorization bypass. **Note:** The issue can only lead to unintended access if heimdall is configured with an "allow all" default rule. Since v0.16.0, heimdall enforces secure defaults and refuses to start with such a configuration unless this enforcement is explicitly disabled (e.g. via `--insecure-skip-secure-default-rule-enforcement` or the broader `--insecure` flag). ### Details Consider the following rule configuration: ```yaml id: rule-1 match: routes: - path: /admin/** execute: # configured to require authentication and authorization # ... ``` If an adversary sends a request such as `/admin%2fsecret`, neither is the above rule matched, nor is the request rejected (as would be expected when `allow_encoded_slashes` is set to `off`). Instead, the default rule (if configured) will be executed. If the configured default rule is overly permissive (e.g. allowing anonymous access), and the upstream service interprets `%2f` as a path separator, the request may ultimately be processed as `/admin/secret`. This results in the request being authorized based on a different path than the one processed by the upstream service, leading to authorization bypass. ### Impact Bypass of access control policies enforced by heimdall may lead to the following consequences: * Access to or modification of data that should be restricted * Invocation of functionality that is expected to require authentication or authorization * In certain configurations, escalation of privileges depending on the exposed functionality ### Wor
Properties
- ghsa_id
- GHSA-43jv-5j4x-qv67
- severity
- high
- summary
- Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation
- cve_id
- GHSA-43jv-5j4x-qv67
- is_ghsa_only
- true
- ghsa_published
- 2026-04-25T23:29:40Z
- source_url
- https://github.com/advisories/GHSA-43jv-5j4x-qv67
- ghsa_updated
- 2026-04-25T23:29:42Z
Related Entities (5)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph