PT-2026-99715 · Nezha · Nezha

·

CVE-2026-101087

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions Nezha versions 2.0.10 through 2.3.2
Description The software uses a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs. However, the denylist fails to cover specific IPv6 transition ranges, namely the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix 64:ff9b:1::/48. Since these addresses satisfy the netip.Addr.IsGlobalUnicast check in Go, the URL validator accepts them. An authenticated user with webhook configuration privileges may cause the dashboard to send requests to restricted IPv6 endpoints, provided the network environment uses non-standards-compliant routing for these transition ranges.
Recommendations Update to version 2.3.3.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101087
GHSA-JR2J-7HVH-H4Q9

Affected Products

Nezha