哪吒(Nezha)版本 2.0.10 至 2.3.2 使用受限的 HTTP 客户端来验证用户可配置的 Webhook 通知和动态 DNS(DDNS)URL。然而,其拒绝列表(denylist)未涵盖 IPv6 过渡地址范围,具体包括 6to4 前缀 2002::/16 以及用于 IPv4/IPv6 转换的本地使用前缀 64:ff9b:1::/48。由于这些地址能够通过 Go 语言 netip.Addr 类型的 IsGlobalUnicast 检查,URL 验证器会错误地接受它们。 经过身份验证的用户若能配置 Web
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101090 | 9.8 CRITICAL | Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri |
| CVE-2026-101085 | 6.5 MEDIUM | Nezha before 2.3.8 Denial of Service via Alert Rule |
| CVE-2026-101086 | 6.5 MEDIUM | Nezha Dashboard before 2.3.5 Task Type Validation Bypass |
| CVE-2026-101088 | 5.3 MEDIUM | Nezha before 2.3.1 Denial of Service via Concurrent Server Delete |
| CVE-2026-101089 | 3.1 LOW | Nezha before 2.2.7 Information Disclosure via /api/v1/profile |
No comments yet