Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nezha — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in nezha, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with Nezha, an open-source web application developed by the software vendor Nezha Team. The collection focuses on reported defects, including memory corruption, input validation errors, and privilege escalation issues, covering advisory publications from 2021 through the present day. Readers can track the vendor's security advisories, analyze the prevalence of specific weakness classes, and review the complete vulnerability history for this product. The data presented here supports security teams in assessing risk exposure, identifying recurring patterns in software bugs, and planning remediation efforts based on historical trends.

Vendor: nezhahq

CVE ID Title CVSS Severity Published
CVE-2026-105113 Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock CWE-667 6.5 Medium 2026-10-03
CVE-2026-105112 Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints CWE-362 5.3 Medium 2026-10-03
CVE-2026-101090 Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri CWE-601 9.8 Critical 2026-09-27
CVE-2026-101089 Nezha before 2.2.7 Information Disclosure via /api/v1/profile CWE-522 3.1 Low 2026-09-27
CVE-2026-101088 Nezha before 2.3.1 Denial of Service via Concurrent Server Delete CWE-367 5.3 Medium 2026-09-27
CVE-2026-101087 Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6 CWE-918 4.3 Medium 2026-09-27
CVE-2026-101086 Nezha Dashboard before 2.3.5 Task Type Validation Bypass CWE-269 6.5 Medium 2026-09-27
CVE-2026-101085 Nezha before 2.3.8 Denial of Service via Alert Rule CWE-197 6.5 Medium 2026-09-27
CVE-2026-62283 Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check CWE-639 9.9 Critical 2026-08-21
CVE-2026-59155 Nezha Monitoring: DDNS and Notification credential exposure via unredacted list API CWE-200 - - 2026-07-10
CVE-2026-53523 Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection CWE-601 6.8 Medium 2026-06-12
CVE-2026-53522 Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS CWE-770 6.5 Medium 2026-06-12
CVE-2026-53521 Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context CWE-863 6.4 Medium 2026-06-12
CVE-2026-53520 Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing CWE-284 6.5 Medium 2026-06-12
CVE-2026-53519 Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key CWE-22 9.1 Critical 2026-06-12
CVE-2026-49397 Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data CWE-200 5.3 Medium 2026-06-12
CVE-2026-49396 Nezha Monitoring: Cross-site GET request can trigger stored cron commands on a victim's agents CWE-352 7.1 High 2026-06-12
CVE-2026-48119 Nezha Monitoring: Authenticated agents can forge service-monitor results for other users' services CWE-862 7.1 High 2026-06-12
CVE-2026-47124 Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members CWE-200 6.5 Medium 2026-06-12
CVE-2026-47120 Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) CWE-862 7.1 High 2026-06-12
CVE-2026-46717 Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification CWE-863 7.7 High 2026-06-12
CVE-2026-46716 Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron CWE-78 9.9 Critical 2026-06-12
CVE-2026-47268 Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dashboard host CWE-918 6.4 Medium 2026-06-12

All 23 known CVE vulnerabilities affecting nezha with full Chinese analysis, references, and POCs where available.