GHSA-4jgr-pg2m-m988High▾ TwilightHeimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When Heimdall operates in proxy mode, it constructs the Forwarded HTTP header after executing the matched rule pipeline by inserting the incoming request's Host header value directly into the header string without sanitizing commas or semicolons. This allows an attacker to inject additional parameters into the Forwarded header, potentially spoofing IP addresses for upstream services.
File: proxy/request_context.go (line 201)
entry := "for=" + clientIP + ";host=" + in.Host + ";proto=" + proto
Go's net/http allows commas and semicolons in Host header values. No sanitization is applied before string concatenation.
# Inject a spoofed IP into the Forwarded header
curl -s -H "Host: evil.com,for=127.0.0.1" \
"http://TARGET:PORT/protected-resource"
This produces the following Forwarded header sent to the upstream service:
Forwarded: for=1.2.3.4;host=evil.com, for=127.0.0.1;proto=http
Upstream services that parse the Forwarded header according to RFC 7239 will see two entries. If the service trusts the last or any for= value, the attacker successfully spoofs 127.0.0.1 as the client IP.
# More targeted attack: spoof to bypass IP allowlist
curl -s -H "Host: legit.com;for=10.0.0.1;proto=https,for=192.168.1.1" \
"http://TARGET:PORT/admin-panel"
for= value, believing the request originates from an internal/trusted IPForwarded header.github.com/dadrus/heimdall <= 0.17.16Upgrade to a patched release:
github.com/dadrus/heimdall 0.17.17Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57209HighHeimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2020-3478High· 8.1A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device
CVE-2020-3577High· 7.4A vulnerability in the ingress packet processing path of Cisco Firepower Threat Defense (FTD) Software for interfaces that are configured either as Inline Pair or in Passive mode could allow an unauthenticated, adjacent attacker to cause…
CVE-2025-13462Low· 3.3The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK
CVE-2020-3317High· 7.5A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances