Skip to content

Known CVE

Heimdall - Host Header Injection & Open Redirect

LinuxServer.io Heimdall 2.6.3-ls307 contains a host header injection caused by improper validation of user-supplied HTTP headers `X-Forwarded-Host` and `Referer`, letting unauthenticated remote attackers perform host header injection and open redirect attacks, exploit requires no special privileges.

CVE-2025-50578

Medium2025

cve2025 · heimdall · redirect · host-header · oos

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website