CVE-2025-50578Disclosure(linuxserver / docker-heimdall)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-74CWE-601

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • docker-heimdall

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
docker-heimdall

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-02: 1Technical Details · 2026-04-02: 104-02
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-50578 - medium 🚨 Heimdall - Host Header Injection & Open Redirect > http://LinuxServer.io Heimdall 2.6.3-ls307 contains a host header injection caused by improp... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-50578 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2025-50578 is disclosed for Heimdall 2.6.3-ls307, detailing a host header injection and open redirect flaw, with a detection PoC referenced via Project Discovery’s library.

    00011323
    905 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxserverdocker-heimdall2.6.3-ls307--

Explore more