哪吒(Nezha)是一款服务器和网站监控工具。在版本 >= 2.2.11 且 < 2.3.1 中,服务哨兵工作者(service/singleton/servicesentinel.go)存在对先前报告的空指针解引用拒绝服务漏洞(GHSA-qjpp-gffx-2wm9)的不完全修复。2026-07-21 的修复虽然在 锁的保护下重新验证了服务生命周期,但重复使用了已被捕获、现已过期的 reporter 指针,且未对 Server 重新进行验证;此外,该锁并未保护 。拥有成员角色权限并拥有某个 Agent 的认证用户
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101090 | 9.8 CRITICAL | Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri |
| CVE-2026-101085 | 6.5 MEDIUM | Nezha before 2.3.8 Denial of Service via Alert Rule |
| CVE-2026-101086 | 6.5 MEDIUM | Nezha Dashboard before 2.3.5 Task Type Validation Bypass |
| CVE-2026-101087 | 4.3 MEDIUM | Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6 |
| CVE-2026-101089 | 3.1 LOW | Nezha before 2.2.7 Information Disclosure via /api/v1/profile |
No comments yet