CVE-2025-50578: Input Validation

Published Jul 30, 2025
·
Updated

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically X-Forwarded-Host and Referer. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.

Affected Software

2 affected components
LinuxServer.io heimdall
LinuxServer Docker-heimdall=2.6.3-ls307

Event History

Jul 30, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-50578?

CVE-2025-50578 is considered a high-severity vulnerability due to its potential for exploitation via Host Header Injection and Open Redirect attacks.

2

How do I fix CVE-2025-50578?

To fix CVE-2025-50578, ensure you update LinuxServer.io heimdall to the latest version that addresses this vulnerability.

3

Who is affected by CVE-2025-50578?

CVE-2025-50578 affects users of LinuxServer.io heimdall version 2.6.3-ls307 and potentially earlier versions.

4

What types of attacks can exploit CVE-2025-50578?

CVE-2025-50578 can be exploited to perform Host Header Injection and Open Redirect attacks, which may lead to unauthorized access or data exposure.

5

Can CVE-2025-50578 be exploited by authenticated users?

No, CVE-2025-50578 can be exploited by unauthenticated remote attackers, making it a serious risk for public-facing services.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203