SSRF Vulnerability in Heimdall by LinuxServer
CVE-2026-107449

3.4LOW

Key Information:

Status
Vendor
CVE Published:
8 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-107449?

The Heimdall application from LinuxServer is vulnerable to Server-Side Request Forgery (SSRF) due to its insufficient protection mechanisms. While the SafeUrlFetcher is intended to mitigate SSRF risks, it is only applied to the ItemController. Other endpoints, like POST /test_config and GET /get_stats, are vulnerable to CSRF attacks, allowing an unauthenticated attacker to exploit the SupportedApps::execute() method. This vulnerability enables attackers to make arbitrary requests to internal hosts and ports, such as 169.254.169.254, potentially exposing sensitive information and server statuses.

Affected Version(s)

Heimdall 0 <= 2.8.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.