VulnSea

github.com/nezhahq/nezha vulnerabilities

CVEs whose affected-version data names the github.com/nezhahq/nezha package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

12 CVEsRSS

GHSA-rf68-8gjr-36q7Low
1w ago

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

Sunlitnezhahq · github.com/nezhahq/nezhavia OSV
CVE-2026-62283Critical· 9.9
1mo ago

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_strea…

Midnightnezhahq · github.com/nezhahq/nezhaEPSS 0.37%via NVD
GHSA-q6xx-5vr8-p898Critical· 9.9
2mo ago

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Midnightnezhahq · github.com/nezhahq/nezhavia GHSA
CVE-2026-53520Medium· 6.5
2mo ago

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.28%via GHSA
CVE-2026-53521Medium· 6.4
2mo ago

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context

Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.23%via GHSA
CVE-2026-53519Critical· 9.1PoC
2mo ago

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Abyssalnezhahq · github.com/nezhahq/nezhaEPSS 1.9%via GHSA
CVE-2026-53522Medium· 6.5
2mo ago

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.29%via GHSA
CVE-2026-53523Medium· 6.8
2mo ago

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.24%via GHSA
GHSA-ww5p-j6cj-6mqqMedium
2mo ago

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

Sunlitnezhahq · github.com/nezhahq/nezhavia GHSA
CVE-2026-49396High· 7.1
3mo ago

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

Twilightnezhahq · github.com/nezhahq/nezhaEPSS 0.12%via GHSA
CVE-2026-49397Medium· 5.3
3mo ago

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.25%via GHSA
CVE-2026-48119High· 7.1
3mo ago

Nezha's authenticated agents can forge service-monitor results for other users' services

Nezha's authenticated agents can forge service-monitor results for other users' services

Twilightnezhahq · github.com/nezhahq/nezhaEPSS 0.27%via OSV
github.com/nezhahq/nezha vulnerabilities (CVEs) · VulnSea