github.com/nezhahq/nezha
Go16 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/nezhahq/nezhapage 1 of 1
- CVE-2026-101090CRITICALCVSS 9.8EG 9.82026-09-27
vulnerable: 2.2.3
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied H…
- CVE-2026-46716CRITICALCVSS 9.9EG 9.9fixed in 1.14.15-0.20260517022419-d7526351cf972026-05-23
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbit…
- CVE-2026-46717HIGHCVSS 7.7EG 7.7fixed in 1.14.15-0.20260517022419-d06d539d34c12026-05-23
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notifi…
- CVE-2026-47120HIGHCVSS 7.1EG 7.1fixed in 1.14.15-0.20260517022419-d7526351cf972026-05-23
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check). …
- CVE-2026-47124MEDIUMCVSS 6.5EG 6.5fixed in 1.14.15-0.20260517034128-05e5da2535192026-05-23
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.9, any authenticated non-admin member can connect to the server-status WebSocket and receive telemetry…
- CVE-2026-47268MEDIUMCVSS 6.4EG 6.4fixed in 2.0.102026-05-29
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.10, an authenticated Nezha dashboard user can create or update a DDNS profile with provider webhook a…
- CVE-2026-48119HIGHCVSS 7.1EG 7.1fixed in 1.14.15-0.20260521020202-02129f16fb15 or 2.0.12, by version range2026-06-01
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authenticated agents can forge service-monitor results for other users' services. This issue has …
- CVE-2026-49396HIGHCVSS 7.1EG 7.1fixed in 2.0.142026-06-10
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.0.14, cross-site GET request can trigger stored cron commands on a victim's agents. This issue has been …
- CVE-2026-49397MEDIUMCVSS 5.3EG 5.3fixed in 2.0.142026-06-10
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking n…
- CVE-2026-53519CRITICALCVSS 9.1EG 9.1fixed in 2.0.132026-06-12
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose raw string starts with /dashboard as an adm…
- CVE-2026-53520MEDIUMCVSS 6.5EG 6.5fixed in 2.1.02026-06-12
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing. Th…
- CVE-2026-53521MEDIUMCVSS 6.4EG 6.4fixed in 2.1.02026-06-12
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /server/{id} accepts and persists nonexistent ddns_profiles IDs for a member-owned server. I…
- CVE-2026-53522MEDIUMCVSS 6.5EG 6.5fixed in 2.2.02026-06-12
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the Nezha dashboard exposes two endpoints that create long-lived WebSocket streams to monitored age…
- CVE-2026-53523MEDIUMCVSS 6.8EG 6.8fixed in 2.2.02026-06-12
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRedirectURL function in oauth2.go:22-29 constructs the OAuth2 callback URL by concatenating …
- CVE-2026-59155MEDIUMCVSS 6.9EG 6.9fixed in 2.2.52026-07-10
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API cr…
- CVE-2026-62283CRITICALCVSS 9.9EG 9.9fixed in 2.0.102026-08-21
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.…
Check whether github.com/nezhahq/nezha is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/nezhahq/nezha CVEs against the assets you own.
Book a Demo →