CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-107449: Heimdall 0 through 2.8.3

CVE-2026-107449. CVSS 3.1 base score 3.4 (LOW, Vendor/CNA).

Affected technology

Heimdall · 0 through 2.8.3
linuxserver

Description’s affected range: through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute()

Component: Enhanced app test/livestats (test_config, get_stats)
Function: SupportedApps::execute
File: app/SupportedApps.php, app/Http/Controllers/ItemController.php

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

And thus an unauthenticated attacker can force the server to send requests to arbitrary internal hosts and ports (including 169.254.169.254) and read a status/port oracle in addition to partial response data. Vendor/CNA’s CVSS 3.1 assessment (base score 3.4/10) rates confidentiality impact as low; integrity and availability impact as none.

Published

CWE
CWE-918
CCR priority
13.6 /100 (P5)
CVSS 3.1
3.4 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N · Vendor/CNA
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-107449.html