Browse all 4 CVE security advisories affecting dadrus. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-42274 | Heimdall: Authorization bypass via path normalization mismatch — heimdallCWE-35 | 5.3AI | MediumAI | 2026-05-08 |
| CVE-2026-42273 | Heimdall: Case-sensitive host matching may lead to policy bypass — heimdallCWE-436 | 5.3AI | MediumAI | 2026-05-08 |
| CVE-2026-42272 | Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation — heimdallCWE-436 | 9.1AI | CriticalAI | 2026-05-08 |
| CVE-2026-32811 | Heimdall: Path received via Envoy gRPC corrupted when containing query string — heimdallCWE-116 | 8.2 | High | 2026-03-20 |
This page lists every published CVE security advisory associated with dadrus. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.