LinuxServer.io Heimdall 2.6.3-ls307 contains a host header injection caused by improper validation of user-supplied HTTP headers `X-Forwarded-Host` and `Referer`, letting unauthenticated remote attackers perform host header injection and open redirect attacks, exploit requires no special privileges.
id: CVE-2025-50578
info:
name: Heimdall - Host Header Injection & Open Redirect
author: Dhiyane
...