Get real-time updates on Telegram
CVE-2026-107449: Heimdall 0 through 2.8.3
CVE-2026-107449. CVSS 3.1 base score 3.4 (LOW, Vendor/CNA).
Affected technology
Heimdall · 0 through 2.8.3
linuxserver
Description’s affected range: through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute()
Component: Enhanced app test/livestats (test_config, get_stats)
Function: SupportedApps::execute
File: app/SupportedApps.php, app/Http/Controllers/ItemController.php
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · User interaction required
What an attacker can do
And thus an unauthenticated attacker can force the server to send requests to arbitrary internal hosts and ports (including 169.254.169.254) and read a status/port oracle in addition to partial response data. Vendor/CNA’s CVSS 3.1 assessment (base score 3.4/10) rates confidentiality impact as low; integrity and availability impact as none.
- CWE
- CWE-918
- CCR priority
- 13.6 /100 (P5)
- CVSS 3.1
- 3.4 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N · Vendor/CNA
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 08:49:39.219831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-107449.html