SSRF Vulnerability in Heimdall by LinuxServer
CVE-2026-107449
Key Information:
- Vendor
Linuxserver
- Status
- Vendor
- CVE Published:
- 8 October 2026
Badges
What is CVE-2026-107449?
The Heimdall application from LinuxServer is vulnerable to Server-Side Request Forgery (SSRF) due to its insufficient protection mechanisms. While the SafeUrlFetcher is intended to mitigate SSRF risks, it is only applied to the ItemController. Other endpoints, like POST /test_config and GET /get_stats, are vulnerable to CSRF attacks, allowing an unauthenticated attacker to exploit the SupportedApps::execute() method. This vulnerability enables attackers to make arbitrary requests to internal hosts and ports, such as 169.254.169.254, potentially exposing sensitive information and server statuses.
Affected Version(s)
Heimdall 0 <= 2.8.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
