S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Apr 2, 2026

CVE-2025-50578 Scanner

CVE-2025-50578 Scanner - Open Redirect vulnerability in Heimdall

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-50578
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Heimdall is a web-based application dashboard for organizing access to various services and managing them effectively. It is primarily used by system administrators and home users who want a centralized interface for all their server applications and services. Developed by LinuxServer.io, Heimdall provides a user-friendly interface for managing bookmarks and accessing web applications. It is often deployed in environments where multiple software services need to be accessed and managed. The application is popular due to its open-source nature and flexibility in integration with various services. Heimdall can be accessed via a web browser, making it a versatile tool for both personal and small business use.

The Open Redirect vulnerability detected in Heimdall allows attackers to manipulate the host header and redirect users to arbitrary destinations. This vulnerability is caused by improper validation of the `X-Forwarded-Host` and `Referer` HTTP headers. By exploiting this flaw, attackers can effectively perform phishing attacks, UI redress, or session theft. Open Redirect vulnerabilities are significant as they allow attackers to exploit user trust and redirect traffic away from the intended destination. This could lead to exposure of user credentials and other sensitive information. Addressing this flaw is crucial to maintaining the application's security integrity.

Technically, the vulnerability revolves around the improper handling and validation of HTTP headers `X-Forwarded-Host` and `Referer` in Heimdall version 2.6.3-ls307. Attackers utilizing this vulnerability can inject arbitrary host headers, effectively executing open redirect attacks. The exploitation process does not require authentication, which makes it easier for remote attackers to exploit. The vulnerability is typically exploited by using specially crafted HTTP requests that manipulate these headers. Proper validation and filtering of headers can mitigate this issue effectively. The attack can be executed remotely and does not necessitate privileged access to the target system.

Exploitation of this vulnerability can have severe consequences, such as users being redirected to malware-laden or phishing sites. This could lead to the compromise of sensitive data such as login credentials. An attacker could use this vulnerability to conduct man-in-the-middle attacks, gaining access to secure communications and personal data. The redirection also poses risks of credibility damage to organizations using Heimdall, as users may associate the redirected malicious content with the legitimate site. Organizations might face reputational and financial damages due to the exploitation of this vulnerability. It is crucial to address this vulnerability to prevent potential exploitation.

REFERENCES

Solution Advice
  • Update Heimdall to the latest version available to mitigate known vulnerabilities.
  • Implement strict validation and sanitization of HTTP header inputs to prevent injection attacks.
  • Ensure secure configurations to limit exposure to potential redirect attacks.
  • Regularly audit and test for open redirects within application deployments.
  • Use security tools to automate detection of such vulnerabilities in web applications.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.