Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nezhahq — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting nezhahq. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the vendor nezhahq, focusing on hardware and firmware weaknesses within the broader hardware and software ecosystem. It collects data spanning recent years, covering issues ranging from memory corruption to improper input validation in related components. Readers can track the vendor's security advisories, understand the specific weakness classes present in their products, and review the historical vulnerability profile without needing to parse individual CVE entries. The collection highlights trends in firmware update mechanisms, driver behavior, and underlying system design flaws that impact devices manufactured or branded by nezhahq. By consolidating these records, the page serves as a reference for assessing the security posture of the vendor's product line over time. It provides a structured view of recurring defect patterns, allowing users to identify common failure modes without searching through disparate databases. This aggregation helps stakeholders evaluate risk exposure and monitor remediation efforts across the vendor's diverse product portfolio.

Top products by nezhahq: nezha
CVE ID Title CVSS Severity Published
CVE-2026-105113 Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock — nezha CWE-667 6.5 Medium 2026-10-03
CVE-2026-105112 Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints — nezha CWE-362 5.3 Medium 2026-10-03
CVE-2026-101090 Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri — nezha CWE-601 9.8 Critical 2026-09-27
CVE-2026-101089 Nezha before 2.2.7 Information Disclosure via /api/v1/profile — nezha CWE-522 3.1 Low 2026-09-27
CVE-2026-101088 Nezha before 2.3.1 Denial of Service via Concurrent Server Delete — nezha CWE-367 5.3 Medium 2026-09-27
CVE-2026-101087 Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6 — nezha CWE-918 4.3 Medium 2026-09-27
CVE-2026-101086 Nezha Dashboard before 2.3.5 Task Type Validation Bypass — nezha CWE-269 6.5 Medium 2026-09-27
CVE-2026-101085 Nezha before 2.3.8 Denial of Service via Alert Rule — nezha CWE-197 6.5 Medium 2026-09-27
CVE-2026-62283 Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check — nezha CWE-639 9.9 Critical 2026-08-21
CVE-2026-59155 Nezha Monitoring: DDNS and Notification credential exposure via unredacted list API — nezha CWE-200 - - 2026-07-10
CVE-2026-53523 Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection — nezha CWE-601 6.8 Medium 2026-06-12
CVE-2026-53522 Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS — nezha CWE-770 6.5 Medium 2026-06-12
CVE-2026-53521 Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context — nezha CWE-863 6.4 Medium 2026-06-12
CVE-2026-53520 Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing — nezha CWE-284 6.5 Medium 2026-06-12
CVE-2026-53519 Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key — nezha CWE-22 9.1 Critical 2026-06-12
CVE-2026-49397 Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data — nezha CWE-200 5.3 Medium 2026-06-12
CVE-2026-49396 Nezha Monitoring: Cross-site GET request can trigger stored cron commands on a victim's agents — nezha CWE-352 7.1 High 2026-06-12
CVE-2026-48119 Nezha Monitoring: Authenticated agents can forge service-monitor results for other users' services — nezha CWE-862 7.1 High 2026-06-12
CVE-2026-47124 Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members — nezha CWE-200 6.5 Medium 2026-06-12
CVE-2026-47120 Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) — nezha CWE-862 7.1 High 2026-06-12
CVE-2026-46717 Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification — nezha CWE-863 7.7 High 2026-06-12
CVE-2026-46716 Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron — nezha CWE-78 9.9 Critical 2026-06-12
CVE-2026-47268 Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dashboard host — nezha CWE-918 6.4 Medium 2026-06-12

This page lists every published CVE security advisory associated with nezhahq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.