哪吒监控面板(Nezha Dashboard)在 2.3.5 版本之前,未对服务监控任务类型限制为支持的探针类型。这使得拥有 权限范围的身份验证用户能够通过服务 API 提交特权任务类型。攻击者可利用服务监控与特权操作之间共享的 Protobuf 命名空间,向其授权范围内的智能探针(Agent)投送命令执行或智能探针配置任务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101090 | 9.8 CRITICAL | Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri |
| CVE-2026-101085 | 6.5 MEDIUM | Nezha before 2.3.8 Denial of Service via Alert Rule |
| CVE-2026-101088 | 5.3 MEDIUM | Nezha before 2.3.1 Denial of Service via Concurrent Server Delete |
| CVE-2026-101087 | 4.3 MEDIUM | Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6 |
| CVE-2026-101089 | 3.1 LOW | Nezha before 2.2.7 Information Disclosure via /api/v1/profile |
No comments yet