A server-side request forgery (SSRF) vulnerability was discovered in Heimdall version 2.6.1, specifically within the Add Application feature. This flaw allows remote attackers to perform HTTP requests.
- Heimdall GitHub repository: https://github.com/linuxserver/Heimdall
- OWASP Top 10 - SSRF (A10:2021): https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_(SSRF)
- CWE-918 - Server-Side Request Forgery (SSRF): https://cwe.mitre.org/data/definitions/918.html