LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Jul 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Linuxserver
Linuxserver heimdall |
|
Vendors & Products |
Linuxserver
Linuxserver heimdall |
Wed, 30 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-20 CWE-601 CWE-74 |
|
Metrics |
cvssV3_1
|
Wed, 30 Jul 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-30T00:00:00.000Z
Updated: 2025-07-30T15:43:42.692Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50578

Updated: 2025-07-30T15:43:14.688Z

Status : Awaiting Analysis
Published: 2025-07-30T16:15:28.177
Modified: 2025-07-31T18:42:37.870
Link: CVE-2025-50578

No data.