LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.
History

Thu, 31 Jul 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Linuxserver
Linuxserver heimdall
Vendors & Products Linuxserver
Linuxserver heimdall

Wed, 30 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-601
CWE-74
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Jul 2025 15:30:00 +0000

Type Values Removed Values Added
Description LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-07-30T00:00:00.000Z

Updated: 2025-07-30T15:43:42.692Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50578

cve-icon Vulnrichment

Updated: 2025-07-30T15:43:14.688Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-30T16:15:28.177

Modified: 2025-07-31T18:42:37.870

Link: CVE-2025-50578

cve-icon Redhat

No data.