—
GO-2026-5200
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall
Quick fix
GO-2026-5200 — github.com/dadrus/heimdall: upgrade to the fixed version with the command below.
go get github.com/dadrus/heimdall@v0.17.14Details
Heimdall: Case-sensitive host matching may lead to policy bypass in github.com/dadrus/heimdall
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/dadrus/heimdall
Introduced in:
0Fixed in: 0.17.14Fix
go get github.com/dadrus/heimdall@v0.17.14References
- https://github.com/dadrus/heimdall/security/advisories/GHSA-72h4-mxfc-jx37[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-42273[ADVISORY]
- https://github.com/dadrus/heimdall/commit/3d05e56a9e7ef0355f17482b4322054af4e85943[FIX]
- https://github.com/dadrus/heimdall/pull/3208[FIX]
- https://github.com/dadrus/heimdall/releases/tag/v0.17.14[WEB]