nezhahq nezha

8 known vulnerabilities in nezhahq nezha, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-105113 CVSS 7.1 high Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map…
  • CVE-2026-105112 CVSS 6.0 medium Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to…
  • CVE-2026-101090 CVSS 9.3 critical Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is…
  • CVE-2026-101089 CVSS 2.3 low Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed…
  • CVE-2026-101088 CVSS 6.0 medium Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker…
  • CVE-2026-101087 CVSS 5.3 medium Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the…
  • CVE-2026-101086 CVSS 7.1 high Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users…
  • CVE-2026-101085 CVSS 7.1 high Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create…