Nezha 2.2.7 版本之前存在信息泄露漏洞,GET /api/v1/profile 接口会返回已认证用户的 bcrypt 哈希密码字段。攻击者可以提取密码哈希值,并在没有速率限制或审计日志约束的情况下进行离线密码破解攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101090 | 9.8 CRITICAL | Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri |
| CVE-2026-101085 | 6.5 MEDIUM | Nezha before 2.3.8 Denial of Service via Alert Rule |
| CVE-2026-101086 | 6.5 MEDIUM | Nezha Dashboard before 2.3.5 Task Type Validation Bypass |
| CVE-2026-101088 | 5.3 MEDIUM | Nezha before 2.3.1 Denial of Service via Concurrent Server Delete |
| CVE-2026-101087 | 4.3 MEDIUM | Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6 |
No comments yet