PT-2026-99718 · Nezha · Nezha

·

CVE-2026-101090

·

Published

2026-09-15

·

Updated

2026-09-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nezha version 2.2.3
Description Nezha contains a Host header injection issue in the OAuth2 redirect endpoint. When the optional dashboard host setting is empty, the application reflects the attacker-supplied HTTP Host header into the redirect uri sent to the identity provider instead of using the configured install host. An attacker can induce a victim to start an OAuth2 login using a request with a forged Host header, causing the identity provider to send the victim's authorization code to an attacker-controlled callback URL. This allows the attacker to complete the login or binding flow and take over the account. This issue occurs at the /api/v1/oauth2/{provider} endpoint within the oauth2redirect() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary mitigation, ensure that the dashboard host setting is not left empty and is configured with a valid host value.

Exploit

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101090
GHSA-RF68-8GJR-36Q7
GO-2026-6486

Affected Products

Nezha