CVE-2026-107449

CVE-2026-107449 published: linuxserver Heimdall through 2.8.3 applies its SafeUrlFetcher SSRF protection mechanism only to ItemController; the enhanced-application test and live-stats requests occur via SupportedApps::execute(), a GuzzleHttp client that lacks IP address restrictions....

View full NVD advisory → ← Back to CVE watch