216.73.216.36

CVE-2025-50578

· Published 30/07/2025 16:15 · Modified 31/07/2025 18:42

Labels: CVE-2025-50578 2025-07-30CVE-2025-50578CWE-20[email protected]

Essential information

Published
30/07/2025 16:15
Modified
31/07/2025 18:42
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
linuxserver.io / heimdall cpe:2.3:a:linuxserver.io:heimdall:2.6.3-ls307:*:*:*:*:*:*:*

References