{"id":"CVE-2026-107449","title":"linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP a…","summary":"linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP a…","severity":"low","cvss":3.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N","cwe":["CWE-918"],"vendor":"linuxserver","product":"Heimdall","affected":["Heimdall <= 2.8.3"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T05:17:04.297","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107449","references":[{"url":"https://github.com/kashishtopi/heimdall-unauth-ssrf","label":"cve@mitre.org"},{"url":"https://github.com/linuxserver/Heimdall/blob/9ad5864a80d7025db1e6eab8eb2981c165b0ddff/app/SupportedApps.php","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T05:05:36.679Z","slug":"CVE-2026-107449","body":"## Overview\n\nlinuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP address restrictions. In some realistic installations, the POST /test_config (and GET /get_stats) endpoints are accessible through CSRF, and thus an unauthenticated attacker can force the server to send requests to arbitrary internal hosts and ports (including 169.254.169.254) and read a status/port oracle in addition to partial response data.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":18.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}