PT-2026-99715 · Nezha · Nezha
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Nezha versions 2.0.10 through 2.3.2
Description
The software uses a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs. However, the denylist fails to cover specific IPv6 transition ranges, namely the 6to4 prefix
2002::/16 and the local-use IPv4/IPv6 translation prefix 64:ff9b:1::/48. Since these addresses satisfy the netip.Addr.IsGlobalUnicast check in Go, the URL validator accepts them. An authenticated user with webhook configuration privileges may cause the dashboard to send requests to restricted IPv6 endpoints, provided the network environment uses non-standards-compliant routing for these transition ranges.Recommendations
Update to version 2.3.3.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nezha