Vulnerability GO-2026-6486
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 hours ago
September 28, 2026 at 04:43 PM UTC
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty in github.com/nezhahq/nezha
v0.15.14 - v1.14.14
v0.15.14 - v1.14.14
Summary
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty in github.com/nezhahq/nezha
Details
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty in github.com/nezhahq/nezha
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
12 days ago
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
2.2.3 GHSA-rf68-8gjr-36q7
2.2.3 GHSA-rf68-8gjr-36q7
Unknown
1 month ago
Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha
v1.0.0 - v1.14.14 GO-2026-5119
v1.0.0 - v1.14.14 GO-2026-5119
Unknown
2 months ago
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha
v0.15.14 - v1.14.14 GO-2026-5821
v0.15.14 - v1.14.14 GO-2026-5821
Unknown
2 months ago
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing in github.com/nezhahq/nezha
v0.15.14 - v1.14.14 GO-2026-5824
v0.15.14 - v1.14.14 GO-2026-5824
Unknown
2 months ago
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context in github.com/nezhahq/nezha
v0.15.14 - v1.14.14 GO-2026-5826
v0.15.14 - v1.14.14 GO-2026-5826
Impacted packages
Timeline
Published
2 hours ago
September 28, 2026 at 04:43 PM UTC
Last Modified
1 hour ago
September 28, 2026 at 05:11 PM UTC