Sceawere
Vulnerability Detail
CVE-2026-107449UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Heimdall SSRF via GuzzleHttp
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.4
- Creation Date
- 4h ago
- Vendor
- linuxserver
- Product
- Heimdall
- Attack Type
- CWE-918 Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP address restrictions. In some realistic installations, the POST /test_config (and GET /get_stats) endpoints are accessible through CSRF, and thus an unauthenticated attacker can force the server to send requests to arbitrary internal hosts and ports (including 169.254.169.254) and read a status/port oracle in addition to partial response data.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.4",
"pubDate": "2026-10-08T05:17:04.297Z",
"pubdate": "2026-10-08T05:17:04.297Z",
"executiveSummary": "Linuxserver Heimdall through version 2.8.3 is susceptible to a Server-Side Request Forgery (SSRF) vulnerability. The flaw originates from inconsistent application of security controls; while the ItemController implements a SafeUrlFetcher mechanism, the SupportedApps::execute() function utilizes a GuzzleHttp client that fails to enforce IP address or network destination restrictions.\nThis vulnerability allows an attacker to manipulate the server into performing arbitrary HTTP requests against internal infrastructure. In environments where the application's configuration test and statistics endpoints are susceptible to Cross-Site Request Forgery (CSRF), an unauthenticated attacker can effectively bypass network perimeter security.\nThe risk is significant, as it enables the exploitation of internal services, including cloud metadata services such as 169.254.169.254. By leveraging the application as a proxy, an attacker can conduct port scanning, perform reconnaissance on internal-only network resources, and potentially exfiltrate sensitive data or manipulate internal services that rely on implicit trust based on originating IP addresses.\nExploitation requires no authentication if the target instance is vulnerable to CSRF, enabling remote attackers to weaponize the application's request-handling capabilities to target the underlying host or the surrounding local network infrastructure.",
"technicalDetails": "The vulnerability resides in the discrepancy between how external URLs are handled across different application modules. Heimdall implements a SafeUrlFetcher class intended to sanitize and restrict destination URLs during application-related operations within the ItemController. However, this protection is not globally enforced. Specifically, the SupportedApps::execute() function, responsible for handling 'test_config' and 'get_stats' requests, bypasses this safeguard entirely.\nThe root cause is the utilization of an unconfigured GuzzleHttp client within SupportedApps::execute() that lacks validation or filtering logic for the target destination host. When these endpoints are triggered, the application performs an outgoing network request using the provided input without verifying if the target resides in a restricted range (e.g., local loopback, RFC1918 private address space, or cloud metadata services).\nThe attack flow begins when an attacker triggers the POST /test_config or GET /get_stats endpoints. If the application is deployed in a manner where these endpoints are reachable via CSRF, an attacker can craft a malicious request that forces the server to initiate an HTTP connection to arbitrary internal hosts and ports. Because the underlying GuzzleHttp client does not implement network-level egress filtering, it will attempt to connect to any reachable internal IP.\nA primary objective for an attacker in this scenario is the targeting of the cloud instance metadata service at 169.254.169.254. By manipulating the parameters sent to the supported apps functions, an attacker can coerce the server to interact with this sensitive API. Furthermore, the application acts as a status/port oracle, allowing the attacker to distinguish between successful connections and failures based on the HTTP response codes or latency patterns returned by the application. This facilitates network mapping of the internal infrastructure, as the attacker can probe for open ports and identify active services that are not exposed to the public internet.\nBecause the vulnerability exists in the core execution logic of the application's integration features, it affects all users of Heimdall up to and including version 2.8.3. The lack of authentication for the specific endpoints involved in the exploitation flow, combined with the absence of input validation on destination URLs, creates a high-severity entry point for attackers seeking to transition from public-facing web exploits to full internal network compromise."
}