Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heimdall SSRF via /test_config Endpoint |
Thu, 08 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxserver
Linuxserver heimdall |
|
| Vendors & Products |
Linuxserver
Linuxserver heimdall |
Thu, 08 Oct 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP address restrictions. In some realistic installations, the POST /test_config (and GET /get_stats) endpoints are accessible through CSRF, and thus an unauthenticated attacker can force the server to send requests to arbitrary internal hosts and ports (including 169.254.169.254) and read a status/port oracle in addition to partial response data. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-08T17:35:00.370Z
Reserved: 2026-10-08T04:28:16.780Z
Link: CVE-2026-107449
No data.
Status : Received
Published: 2026-10-08T05:17:04.297
Modified: 2026-10-08T05:17:04.297
Link: CVE-2026-107449
No data.
OpenCVE Enrichment
Updated: 2026-10-08T07:00:10Z
-
CWE-918
Server-Side Request Forgery (SSRF)