github.com/nezhahq/nezha vulnerabilities
CVEs whose affected-version data names the github.com/nezhahq/nezha package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
12 CVEsRSS
GHSA-rf68-8gjr-36q7LowNezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
CVE-2026-62283Critical· 9.9Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_strea…
GHSA-q6xx-5vr8-p898Critical· 9.9Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
CVE-2026-53520Medium· 6.5Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
CVE-2026-53521Medium· 6.4Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
CVE-2026-53519Critical· 9.1PoCNezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
CVE-2026-53522Medium· 6.5Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
CVE-2026-53523Medium· 6.8Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
GHSA-ww5p-j6cj-6mqqMediumNezha Dashboard: DDNS and Notification credential exposure via unredacted list API
Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API
CVE-2026-49396High· 7.1Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
CVE-2026-49397Medium· 5.3Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVE-2026-48119High· 7.1Nezha's authenticated agents can forge service-monitor results for other users' services
Nezha's authenticated agents can forge service-monitor results for other users' services