哪吒(Nezha)版本 2.2.3 中存在一个 OAuth2 重定向端点的 Host 头注入回归漏洞。当可选配置项 为空时, 接口(位于 )会将攻击者提供的 HTTP Host 头直接反射到发送给身份提供者的 参数中,而不是回退使用配置的 。攻击者可通过诱导受害者发起携带伪造 Host 头的 OAuth2 登录请求,使 Nezha 使用该伪造 Host 头生成重定向 URI;若 OAuth2 提供者接受该重定向地址,则受害者的授权码将被发送至攻击者控制的域名,从而使攻击者能够完成 OAuth2 登录/绑定流程并接管
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101085 | 6.5 MEDIUM | Nezha before 2.3.8 Denial of Service via Alert Rule |
| CVE-2026-101086 | 6.5 MEDIUM | Nezha Dashboard before 2.3.5 Task Type Validation Bypass |
| CVE-2026-101088 | 5.3 MEDIUM | Nezha before 2.3.1 Denial of Service via Concurrent Server Delete |
| CVE-2026-101087 | 4.3 MEDIUM | Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6 |
| CVE-2026-101089 | 3.1 LOW | Nezha before 2.2.7 Information Disclosure via /api/v1/profile |
No comments yet