References https://nvd.nist.gov/vuln/detail/CVE-2025-50578 https://github.com/linuxserver/Heimdall/issues/1451 https://medium.com/@juanfelipeoz.rar/cve-2025-50578-exploiting-host-header-injection-open-redirect-in-heimdall-application-733afceff2ea https://avd.aliyun.com/detail?id=AVD-2025-50578 https://www.ddpoc.com/DVB-2026-11038.html https://access.redhat.com/security/cve/cve-2025-50578 https://www.sentinelone.com/vulnerability-database/cve-2025-50578/ https://osv.dev/vulnerability/CVE-2025-50578 https://github.com/advisories/GHSA-2c6m-gpf4-cfgp
Related VulnerabilitiesPoCCVE-2025-50578: Heimdall - Host Header Injection & Open RedirectPoCCVE-2025-54597: Heimdall Application Dashboard < 2.7.3 - Reflected XSSPoCheimdall-dashboard-exposure: Heimdall Application Dashboard - Unauthenticated AccessPoCCVE-2023-50578: Mingsoft MCMS 5.2.9 - SQL Injection