Skip to content

Conversation

@slydetector
Copy link

@slydetector slydetector commented Nov 24, 2025

Description

Overseerr web-ui leaks the origin site URL via the Referer http request header when loading resources from some 3rd party websites. Examples include:

  • Logging in: https://plex.tv/users/<redacted>/avatar?c=<redacted>
  • Loading home page: https://fonts.gstatic.com/s/inter/v20/UcC73FwrK3iLTeHuS_nVMrMxCp50SjIa1ZL7W0Q5nw.woff2
  • Loading settings page: https://secure.gravatar.com/avatar/<redacted>?d=<redacted>

I've got image caching enabled atm, but when disabled, loading images from tmdb & friends also leaks the origin via referer header.

Unless the referrer header is necessary for correct functionality, it would be a good idea to set a site wide referrer policy to no-referrer in the interest of privacy.

Tested with the change I'm not seeing the referer header being sent anymore.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant