CVE-2025-50578: Input Validation
LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically X-Forwarded-Host and Referer. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50578?
CVE-2025-50578 is considered a high-severity vulnerability due to its potential for exploitation via Host Header Injection and Open Redirect attacks.
How do I fix CVE-2025-50578?
To fix CVE-2025-50578, ensure you update LinuxServer.io heimdall to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-50578?
CVE-2025-50578 affects users of LinuxServer.io heimdall version 2.6.3-ls307 and potentially earlier versions.
What types of attacks can exploit CVE-2025-50578?
CVE-2025-50578 can be exploited to perform Host Header Injection and Open Redirect attacks, which may lead to unauthorized access or data exposure.
Can CVE-2025-50578 be exploited by authenticated users?
No, CVE-2025-50578 can be exploited by unauthenticated remote attackers, making it a serious risk for public-facing services.