PT-2026-99718 · Nezha · Nezha
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nezha version 2.2.3
Description
Nezha contains a Host header injection issue in the OAuth2 redirect endpoint. When the optional
dashboard host setting is empty, the application reflects the attacker-supplied HTTP Host header into the redirect uri sent to the identity provider instead of using the configured install host. An attacker can induce a victim to start an OAuth2 login using a request with a forged Host header, causing the identity provider to send the victim's authorization code to an attacker-controlled callback URL. This allows the attacker to complete the login or binding flow and take over the account. This issue occurs at the /api/v1/oauth2/{provider} endpoint within the oauth2redirect() function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, ensure that the
dashboard host setting is not left empty and is configured with a valid host value.Exploit
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nezha