{"schema_version":"1.7.5","id":"GO-2026-4742","published":"2026-03-23T18:14:47Z","modified":"2026-03-23T18:45:15.255052Z","aliases":["CVE-2026-32811","GHSA-r8x2-fhmf-6mxp"],"summary":"Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall","details":"Heimdall: Path received via Envoy gRPC corrupted when containing query string in github.com/dadrus/heimdall","affected":[{"package":{"name":"github.com/dadrus/heimdall","ecosystem":"Go","purl":"pkg:golang/github.com/dadrus/heimdall"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.7.0-alpha"},{"fixed":"0.17.11"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4742.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/dadrus/heimdall/security/advisories/GHSA-r8x2-fhmf-6mxp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32811"},{"type":"FIX","url":"https://github.com/dadrus/heimdall/commit/50321b3007db1ccafdc6b1cfd6bdc3689c19a502"},{"type":"FIX","url":"https://github.com/dadrus/heimdall/pull/3106"},{"type":"WEB","url":"https://github.com/envoyproxy/envoy/blob/105b4acd422d67fcff908ec38d91c7676d079939/api/envoy/service/auth/v3/attribute_context.proto#L146-L147"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-4742"}}