Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101090— Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri

Quick assessment

Affected
nezhahq nezha
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

哪吒(Nezha)版本 2.2.3 中存在一个 OAuth2 重定向端点的 Host 头注入回归漏洞。当可选配置项 为空时, 接口(位于 )会将攻击者提供的 HTTP Host 头直接反射到发送给身份提供者的 参数中,而不是回退使用配置的 。攻击者可通过诱导受害者发起携带伪造 Host 头的 OAuth2 登录请求,使 Nezha 使用该伪造 Host 头生成重定向 URI;若 OAuth2 提供者接受该重定向地址,则受害者的授权码将被发送至攻击者控制的域名,从而使攻击者能够完成 OAuth2 登录/绑定流程并接管

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1133 · External Remote Services
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101090

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri
Source: CVE Program / CVE List V5
Vulnerability Description
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to begin OAuth2 login via a request that reaches Nezha with a forged Host header can cause an attacker-controlled callback URL to be used as the redirect_uri; if the OAuth2 provider accepts it, the victim's authorization code is delivered to the attacker origin, allowing the attacker to complete the OAuth2 login/binding flow and take over the account. This regresses the fix for GHSA-9rc6-8cjv-rcvx and is configuration-dependent (dashboard_host empty). At the time of the advisory no patched version was available.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nezhahq nezha 2.2.3 ~ 2.2.3 -

II. Public POCs for CVE-2026-101090

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101090

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101090 (1)

Other References for CVE-2026-101090 (1)

Same Patch Batch · nezhahq · 2026-09-27 · 6 CVEs total

CVE-2026-101085 6.5 MEDIUM Nezha before 2.3.8 Denial of Service via Alert Rule
CVE-2026-101086 6.5 MEDIUM Nezha Dashboard before 2.3.5 Task Type Validation Bypass
CVE-2026-101088 5.3 MEDIUM Nezha before 2.3.1 Denial of Service via Concurrent Server Delete
CVE-2026-101087 4.3 MEDIUM Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6
CVE-2026-101089 3.1 LOW Nezha before 2.2.7 Information Disclosure via /api/v1/profile

IV. Related Vulnerabilities

V. Comments for CVE-2026-101090

No comments yet


Leave a comment