go

github.com/nezhahq/nezha

View on go registry
28 Total advisories
28 Vulnerabilities
0 Malware

Vulnerabilities

CRITICAL 9.9
Go

GO-2026-5821

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

UNKNOWN
Go

GO-2026-5832

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

MEDIUM 6.4
Go

CVE-2026-53521

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context

CRITICAL 9.1
Go

CVE-2026-53519

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

MEDIUM 6.8
Go

CVE-2026-53523

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

MEDIUM 6.5
Go

CVE-2026-53522

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

MEDIUM 6.5
Go

CVE-2026-53520

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

UNKNOWN
Go

CVE-2026-53519

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key in github.com/nezhahq/nezha

UNKNOWN
Go

GHSA-ww5p-j6cj-6mqq

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API in github.com/nezhahq/nezha

UNKNOWN
Go

CVE-2026-53522

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS in github.com/nezhahq/nezha

UNKNOWN
Go

CVE-2026-53523

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection in github.com/nezhahq/nezha

UNKNOWN
Go

CVE-2026-53520

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing in github.com/nezhahq/nezha

UNKNOWN
Go

CVE-2026-53521

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context in github.com/nezhahq/nezha

UNKNOWN
Go

GHSA-q6xx-5vr8-p898

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha

MEDIUM 5.3
Go

CVE-2026-49397

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

MEDIUM 5.4
Go

CVE-2026-47120

Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)

CRITICAL 9.9
Go

CVE-2026-46716

Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron

HIGH 8.5
Go

CVE-2026-46717

Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification

MEDIUM 6.4
Go

CVE-2026-47268

Nezha's authenticated DDNS webhook configuration allows blind SSRF from the dashboard host

HIGH 7.1
Go

CVE-2026-48119

Nezha's authenticated agents can forge service-monitor results for other users' services

MEDIUM 6.5
Go

CVE-2026-47124

Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members

HIGH 7.1
Go

CVE-2026-49396

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

UNKNOWN
Go

CVE-2026-46717

Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification in github.com/nezhahq/nezha

UNKNOWN
Go

CVE-2026-47120

Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) in github.com/nezhahq/nezha

UNKNOWN
Go

CVE-2026-49397

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data in github.com/nezhahq/nezha

UNKNOWN
Go

CVE-2026-47124

Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members in github.com/nezhahq/nezha

UNKNOWN
Go

CVE-2026-49396

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents in github.com/nezhahq/nezha

UNKNOWN
Go

CVE-2026-46716

Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron in github.com/nezhahq/nezha

Ready to move

Start Securing

Free, no credit card | First findings in minutes