CVE-2026-107449: Linuxserver Heimdall

Low severity, CVSS 3.4. EPSS: 0.2% chance of exploitation in the next 30 days.

linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP address restrictions. In some realistic installations, the POST /test_config (and GET /get_stats) endpoints are accessible through CSRF, and thus an unauthenticated attacker can force the server to send requests to arbitrary internal hosts and ports (including 169.254.169.254) and read a status/port oracle in addition to partial response data.

Affected products

Published 2026-10-08. Last modified 2026-10-08.