LOW
linuxserver
CVE published 2026-10-08
CVE-2026-107449
CVE-2026-107449 is a vulnerability in linuxserver Heimdall through version 2.8.3. The vulnerability applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP address restrictions. In some realistic installations, the POST /test_config (and GET /get_stats) endpoints [truncated]