---
id: CVE-2026-107449
title: >-
  linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection
  mechanism only to ItemController; the enhanced-application test and live-stats
  requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP
  a…
summary: >-
  linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection
  mechanism only to ItemController; the enhanced-application test and live-stats
  requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP
  a…
severity: low
cvss: 3.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'
cwe:
  - CWE-918
vendor: linuxserver
product: Heimdall
affected:
  - Heimdall <= 2.8.3
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T05:17:04.297'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107449'
references:
  - url: 'https://github.com/kashishtopi/heimdall-unauth-ssrf'
    label: cve@mitre.org
  - url: >-
      https://github.com/linuxserver/Heimdall/blob/9ad5864a80d7025db1e6eab8eb2981c165b0ddff/app/SupportedApps.php
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T05:05:36.679Z'
---

## Overview

linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP address restrictions. In some realistic installations, the POST /test_config (and GET /get_stats) endpoints are accessible through CSRF, and thus an unauthenticated attacker can force the server to send requests to arbitrary internal hosts and ports (including 169.254.169.254) and read a status/port oracle in addition to partial response data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
