VYPR

heimdall-unauth-ssrf

by Kashishtopi

CVEs (1)

  • CVE-2026-107449LowOct 8, 2026
    risk 0.22cvss 3.4epss —

    linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP address restrictions. In some realistic…