nezhahq
DevTools & CIoss-project
Top products
Latest CVEs
The 14 most recently published vulnerabilities affecting nezhahq.
- CVE-2026-62283Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check9.9
- CVE-2026-53523Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection6.8
- CVE-2026-53522Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS6.5
- CVE-2026-53521Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context6.4
- CVE-2026-53520Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing6.5
- CVE-2026-53519Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key9.1
- CVE-2026-49397Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data5.3
- CVE-2026-49396Nezha Monitoring: Cross-site GET request can trigger stored cron commands on a victim's agents7.1
- CVE-2026-48119Nezha Monitoring: Authenticated agents can forge service-monitor results for other users' services7.1
- CVE-2026-47124Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members6.5
- CVE-2026-47120Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)7.1
- CVE-2026-46717Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification7.7
- CVE-2026-46716Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron9.9
- CVE-2026-47268Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dashboard host6.4