Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

nezhahq — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting nezhahq. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page documents common weakness and vulnerability aggregations for the vendor nezhahq. It collects security advisories, bug reports, and related vulnerability data associated with nezhahq products and services, covering incidents reported over the past several years. Here, you can track a vendor's advisories to stay informed about their security response timeline, understand a weakness class by analyzing how similar flaws manifest in their ecosystem, and look up a product's vulnerability history to assess long-term risk exposure and patch adoption rates. The data reflects publicly disclosed information and third-party reports, providing a comprehensive view of the security landscape for nezhahq. Users can identify patterns in defect types, evaluate the severity distribution of reported issues, and compare remediation speeds across different product lines. This resource supports security analysts, developers, and procurement teams in making informed decisions about risk mitigation and vendor evaluation. By centralizing these records, the page aims to improve transparency and facilitate proactive security management for stakeholders relying on nezhahq solutions. The information is updated regularly as new disclosures become available, ensuring that users have access to the most current insights.

Top products by nezhahq: nezha
CVE IDTitleCVSSSeverityPublished
CVE-2026-53523 Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection — nezhaCWE-601 6.8 Medium2026-06-12
CVE-2026-53522 Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS — nezhaCWE-770 6.5 Medium2026-06-12
CVE-2026-53521 Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context — nezhaCWE-863 6.4 Medium2026-06-12
CVE-2026-53520 Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing — nezhaCWE-284 6.5 Medium2026-06-12
CVE-2026-53519 Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key — nezhaCWE-22 9.1 Critical2026-06-12
CVE-2026-49397 Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data — nezhaCWE-200 5.3 Medium2026-06-12
CVE-2026-49396 Nezha Monitoring: Cross-site GET request can trigger stored cron commands on a victim's agents — nezhaCWE-352 7.1 High2026-06-12
CVE-2026-48119 Nezha Monitoring: Authenticated agents can forge service-monitor results for other users' services — nezhaCWE-862 7.1 High2026-06-12
CVE-2026-47124 Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members — nezhaCWE-200 6.5 Medium2026-06-12
CVE-2026-47120 Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) — nezhaCWE-862 7.1 High2026-06-12
CVE-2026-46717 Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification — nezhaCWE-863 7.7 High2026-06-12
CVE-2026-46716 Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron — nezhaCWE-78 9.9 Critical2026-06-12
CVE-2026-47268 Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dashboard host — nezhaCWE-918 6.4 Medium2026-06-12

This page lists every published CVE security advisory associated with nezhahq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.