Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

nezhahq — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting nezhahq. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the vendor nezhahq, categorized by their respective vulnerability types and classification tags. It collects data on security flaws ranging from remote code execution and buffer overflows to information disclosure and denial-of-service issues reported across the vendor's product ecosystem. The timeline covered spans from the earliest disclosed incidents to the most recent updates, ensuring a comprehensive historical view of security incidents. Here, you can track the vendor's security advisories over time to understand their patching speed and response protocols. You can also delve into specific weakness classes to identify recurring patterns or architectural weaknesses in the software design. Additionally, this resource allows you to look up individual products' vulnerability histories to assess risk exposure and prioritize remediation efforts. By consolidating these diverse data points, the page provides a structured overview for security professionals, auditors, and developers who need to evaluate the security posture of nezhahq's offerings. This aggregated view helps in benchmarking against industry standards and identifying potential gaps in security management practices without requiring manual retrieval of individual reports.

Found 14 results / 14Clear Filters
Top products by nezhahq: nezha
CVE IDTitleCVSSSeverityPublished
CVE-2026-59155 Nezha Monitoring: DDNS and Notification credential exposure via unredacted list API — nezhaCWE-200--2026-07-10
CVE-2026-53523 Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection — nezhaCWE-601 6.8 Medium2026-06-12
CVE-2026-53522 Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS — nezhaCWE-770 6.5 Medium2026-06-12
CVE-2026-53521 Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context — nezhaCWE-863 6.4 Medium2026-06-12
CVE-2026-53520 Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing — nezhaCWE-284 6.5 Medium2026-06-12
CVE-2026-53519 Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key — nezhaCWE-22 9.1 Critical2026-06-12
CVE-2026-49397 Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data — nezhaCWE-200 5.3 Medium2026-06-12
CVE-2026-49396 Nezha Monitoring: Cross-site GET request can trigger stored cron commands on a victim's agents — nezhaCWE-352 7.1 High2026-06-12
CVE-2026-48119 Nezha Monitoring: Authenticated agents can forge service-monitor results for other users' services — nezhaCWE-862 7.1 High2026-06-12
CVE-2026-47124 Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members — nezhaCWE-200 6.5 Medium2026-06-12
CVE-2026-47120 Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) — nezhaCWE-862 7.1 High2026-06-12
CVE-2026-46717 Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification — nezhaCWE-863 7.7 High2026-06-12
CVE-2026-46716 Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron — nezhaCWE-78 9.9 Critical2026-06-12
CVE-2026-47268 Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dashboard host — nezhaCWE-918 6.4 Medium2026-06-12

This page lists every published CVE security advisory associated with nezhahq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.