CVE-2026-107449
Received Received - Intake

Heimdall SSRF via Unrestricted GuzzleHttp Requests

Vulnerability report for CVE-2026-107449, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: MITRE

Description

linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP address restrictions. In some realistic installations, the POST /test_config (and GET /get_stats) endpoints are accessible through CSRF, and thus an unauthenticated attacker can force the server to send requests to arbitrary internal hosts and ports (including 169.254.169.254) and read a status/port oracle in addition to partial response data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linuxserver Heimdall 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated Server-Side Request Forgery (SSRF) in linuxserver Heimdall through version 2.8.3. The issue occurs because the SafeUrlFetcher SSRF protection is only applied to ItemController, while other endpoints like POST /test_config and GET /get_stats use a GuzzleHttp client without IP restrictions. An attacker can exploit this to force the server to send requests to arbitrary internal hosts and ports, including 169.254.169.254, and read partial response data.

Detection Guidance

Check if the POST /test_config and GET /get_stats endpoints are accessible without authentication. Use tools like curl to send requests to these endpoints and observe responses. Example: curl -X POST http://<target>/test_config -d '{"url":"http://169.254.169.254"}' to test for SSRF.

Impact Analysis

An attacker could exploit this to access internal services, exfiltrate sensitive data, or interact with internal systems. In default passwordless installations, the POST /test_config endpoint is accessible without authentication, allowing unauthenticated requests to internal hosts. The attacker can also use a status/port oracle to infer the success or failure of their requests.

Compliance Impact

This vulnerability could lead to unauthorized access to internal systems, potentially exposing sensitive data. For GDPR, this may violate principles of data protection and security. For HIPAA, it could compromise protected health information if internal systems are accessed. Organizations may face compliance violations and legal consequences.

Mitigation Strategies

Upgrade Heimdall to the latest version where the SSRF protection is applied consistently. Restrict access to the /test_config and /get_stats endpoints via network policies or authentication. Disable unauthenticated access if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107449. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart