Nezhahq / Nezha
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-101090 | Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri | CRITICAL | 9.3 | Sep 27, 2026 |
| CVE-2026-101089 | Nezha before 2.2.7 Information Disclosure via /api/v1/profile | LOW | 2.3 | Sep 27, 2026 |
| CVE-2026-101088 | Nezha before 2.3.1 Denial of Service via Concurrent Server Delete | MEDIUM | 6.0 | Sep 27, 2026 |
| CVE-2026-101087 | Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6 | MEDIUM | 5.3 | Sep 27, 2026 |
| CVE-2026-101086 | Nezha Dashboard before 2.3.5 Task Type Validation Bypass | HIGH | 7.1 | Sep 27, 2026 |
| CVE-2026-101085 | Nezha before 2.3.8 Denial of Service via Alert Rule | HIGH | 7.1 | Sep 27, 2026 |
| CVE-2026-62283 | Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check | CRITICAL | 9.9 | Aug 21, 2026 |
| CVE-2026-59155 | Nezha Monitoring: DDNS and Notification credential exposure via unredacted list API | MEDIUM | 6.9 | Jul 10, 2026 |
| CVE-2026-53523 | Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection | MEDIUM | 6.8 | Jun 12, 2026 |
| CVE-2026-53522 | Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS | MEDIUM | 6.5 | Jun 12, 2026 |
| CVE-2026-53521 | Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context | MEDIUM | 6.4 | Jun 12, 2026 |
| CVE-2026-53520 | Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing | MEDIUM | 6.5 | Jun 12, 2026 |
| CVE-2026-53519 | Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key | CRITICAL | 9.1 | Jun 12, 2026 |
| CVE-2026-49397 | Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data | MEDIUM | 5.3 | Jun 12, 2026 |
| CVE-2026-49396 | Nezha Monitoring: Cross-site GET request can trigger stored cron commands on a victim's agents | HIGH | 7.1 | Jun 12, 2026 |
| CVE-2026-48119 | Nezha Monitoring: Authenticated agents can forge service-monitor results for other users' services | HIGH | 7.1 | Jun 12, 2026 |
| CVE-2026-47124 | Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members | MEDIUM | 6.5 | Jun 12, 2026 |
| CVE-2026-47120 | Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) | HIGH | 7.1 | Jun 12, 2026 |
| CVE-2026-46717 | Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification | HIGH | 8.5 | Jun 12, 2026 |
| CVE-2026-46716 | Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron | CRITICAL | 9.9 | Jun 12, 2026 |
| CVE-2026-47268 | Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dashboard host | MEDIUM | 6.4 | Jun 12, 2026 |
Showing 1 to 21 of 21 CVEs