github.com/nezhahq/nezha vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-WW5P-J6CJ-6MQQMediumgithub.com/nezhahq/nezha: Nezha Dashboard: DDNS and Notification credential exposure via unredacted list APICVE-2026-53523Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: OAuth2 Redirect URL — Host Header InjectionCVE-2026-53522Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoSCVE-2026-53519Criticalgithub.com/nezhahq/nezha: Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_keyCVE-2026-53521Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile contextCVE-2026-53520Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routingGHSA-Q6XX-5VR8-P898Criticalgithub.com/nezhahq/nezha: Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership checkCVE-2026-49397Mediumgithub.com/nezhahq/nezha: Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing dataCVE-2026-49396Highgithub.com/nezhahq/nezha: Nezha has cross-site GET request that can trigger stored cron commands on a victim's agentsCVE-2026-48119Highgithub.com/nezhahq/nezha: Nezha's authenticated agents can forge service-monitor results for other users' servicesCVE-2026-47268Mediumgithub.com/nezhahq/nezha: Nezha's authenticated DDNS webhook configuration allows blind SSRF from the dashboard hostCVE-2026-47124Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated membersCVE-2026-46716Criticalgithub.com/nezhahq/nezha: Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cronCVE-2026-47120Mediumgithub.com/nezhahq/nezha: Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)CVE-2026-46717Highgithub.com/nezhahq/nezha: Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification

Stop the waste.
Protect your environment with Kodem.