CRITICAL9.9CVE-2026-46716Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron in github.com/nezhahq/nezha >= 1.4.0, < 1.14.15-0.20260517022419-d7526351cf97
CRITICAL9.9CVE-2026-46716Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron in github.com/nezhahq/nezha >= 1.4.0, < 1.14.15-0.20260517022419-d7526351cf97
CRITICAL9.1CVE-2026-53519Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key in github.com/nezhahq/nezha from 0, < 2.0.13
CRITICAL9.1Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key in github.com/nezhahq/nezha
from 0
HIGH8.5Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification in github.com/nezhahq/nezha
>= 1.4.0, < 1.14.15-0.20260517022419-d06d539d34c1
HIGH8.5Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification in github.com/nezhahq/nezha
>= 1.4.0, < 1.14.15-0.20260517022419-d06d539d34c1
HIGH7.1Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents in github.com/nezhahq/nezha
>= 1.0.0, < 2.0.14
HIGH7.1Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents in github.com/nezhahq/nezha
>= 1.0.0
HIGH7.1Nezha's authenticated agents can forge service-monitor results for other users' services
>= 0.20.0, < 1.14.15-0.20260521020202-02129f16fb15
MEDIUM6.8Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection in github.com/nezhahq/nezha
>= 1.0.0, < 2.2.0
MEDIUM6.8Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection in github.com/nezhahq/nezha
>= 1.0.0
MEDIUM6.5Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS in github.com/nezhahq/nezha
>= 1.0.0, < 2.2.0
MEDIUM6.5Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS in github.com/nezhahq/nezha
>= 1.0.0
MEDIUM6.5Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing in github.com/nezhahq/nezha
>= 2.0.14, < 2.1.0
MEDIUM6.5Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing in github.com/nezhahq/nezha
from 0
MEDIUM6.5Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members in github.com/nezhahq/nezha
>= 1.4.0, < 1.14.15-0.20260517034128-05e5da253519
MEDIUM6.5Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members in github.com/nezhahq/nezha
>= 1.4.0, < 1.14.15-0.20260517034128-05e5da253519
MEDIUM6.4Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context in github.com/nezhahq/nezha
>= 2.0.14, < 2.1.0
MEDIUM6.4Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context in github.com/nezhahq/nezha
from 0
MEDIUM6.4Nezha's authenticated DDNS webhook configuration allows blind SSRF from the dashboard host in github.com/nezhahq/nezha in github.com/naiba/nezha
>= 0.20.0, < 2.0.10
MEDIUM5.4Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) in github.com/nezhahq/nezha
>= 1.4.0, < 1.14.15-0.20260517022419-d7526351cf97
MEDIUM5.4Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) in github.com/nezhahq/nezha
>= 1.4.0, < 1.14.15-0.20260517022419-d7526351cf97
MEDIUM5.3Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data in github.com/nezhahq/nezha
>= 2.0.0, < 2.0.14
MEDIUM5.3Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data in github.com/nezhahq/nezha
from 0
—Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API in github.com/nezhahq/nezha
from 0, < 2.2.5
—Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API in github.com/nezhahq/nezha
from 0