CVE-2025-50578

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxserver:heimdall_application_dashboard:2.6.3-ls307:*:*:*:*:*:*:*

History

07 Aug 2025, 18:18

Type Values Removed Values Added
First Time Linuxserver heimdall Application Dashboard
Linuxserver
CPE cpe:2.3:a:linuxserver:heimdall_application_dashboard:2.6.3-ls307:*:*:*:*:*:*:*
References () https://github.com/linuxserver/Heimdall - () https://github.com/linuxserver/Heimdall - Product
References () https://medium.com/@juanfelipeoz.rar/cve-2025-50578-exploiting-host-header-injection-open-redirect-in-heimdall-application-733afceff2ea - () https://medium.com/@juanfelipeoz.rar/cve-2025-50578-exploiting-host-header-injection-open-redirect-in-heimdall-application-733afceff2ea - Exploit, Third Party Advisory
References () https://github.com/linuxserver/Heimdall/issues/1451 - () https://github.com/linuxserver/Heimdall/issues/1451 - Exploit, Issue Tracking

30 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-30 16:15

Updated : 2025-08-07 18:18


NVD link : CVE-2025-50578

Mitre link : CVE-2025-50578


JSON object : View

Products Affected

linuxserver

  • heimdall_application_dashboard
CWE

No CWE.