LOW
Nezha before 2.2.7 Information Disclosure via /api/v1/profile
Published Sep 27, 2026
2.3
LOWCVSS 4.0
EPSS 0.15%
Description
Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rate limiting or audit trail constraints.
Affected products
-
- Version 0StatusaffectedConstraints<2.2.7
- Version 2.2.7StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88024 Advisory
- https://github.com/nezhahq/nezha/security/advisories/GHSA-8jhq-g4gw-rv5f vendor-advisory
- https://www.vulncheck.com/advisories/nezha-before-2.2.7-information-disclosure-via-api-v1-profile third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88024 | Advisory | |
| https://github.com/nezhahq/nezha/security/advisories/GHSA-8jhq-g4gw-rv5f | vendor-advisory | |
| https://www.vulncheck.com/advisories/nezha-before-2.2.7-information-disclosure-via-api-v1-profile | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 27, 2026
Updated Sep 28, 2026
Reserved Sep 27, 2026
Link CVE-2026-101089
CISA Vulnrichment
Updated Sep 28, 2026
ENISA EUVD
EUVD-2026-88024 Assigner VulnCheck
Published Sep 27, 2026
Updated Sep 28, 2026
Exploited since n/a
Link EUVD-2026-88024