Nezha Monitering是Nezha Monitoring组织开源的一款自托管、轻量级的服务器和网站监控及运维工具。 Nezha Monitoring 2.0.13之前版本存在安全漏洞,该漏洞源于dashboard的NoRoute处理器中fallbackToFrontend函数使用strings.HasPrefix而非路径段匹配来验证URL,允许攻击者通过构造如/dashboard../data/config.yaml的输入绕过检查,导致任意文件读取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Nezha Monitoring < 2.0.13 contains a path traversal caused by improper prefix checking in the dashboard's NoRoute handler, letting unauthenticated attackers read arbitrary files via crafted URLs. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-53519.yaml | POC Details |
| CVE-2026-46716 | 9.9 CRITICAL | Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /ap |
| CVE-2026-46717 | 7.7 HIGH | Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /a |
| CVE-2026-47120 | 7.1 HIGH | Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTas |
| CVE-2026-48119 | 7.1 HIGH | Nezha Monitoring: Authenticated agents can forge service-monitor results for other users' |
| CVE-2026-49396 | 7.1 HIGH | Nezha Monitoring: Cross-site GET request can trigger stored cron commands on a victim's ag |
| CVE-2026-53523 | 6.8 MEDIUM | Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection |
| CVE-2026-53520 | 6.5 MEDIUM | Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt |
| CVE-2026-53522 | 6.5 MEDIUM | Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS |
| CVE-2026-47124 | 6.5 MEDIUM | Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated mem |
| CVE-2026-53521 | 6.4 MEDIUM | Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's |
| CVE-2026-47268 | 6.4 MEDIUM | Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dash |
| CVE-2026-49397 | 5.3 MEDIUM | Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-s |
No comments yet