CVE-2026-101090

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to begin OAuth2 login via a request that reaches Nezha with a forged Host header can cause an attacker-controlled callback URL to be used as the redirect_uri; if the OAuth2 provider accepts it, the victim's authorization code is delivered to the attacker origin, allowing the attacker to complete the OAuth2 login/binding flow and take over the account. This regresses the fix for GHSA-9rc6-8cjv-rcvx and is configuration-dependent (dashboard_host empty). At the time of the advisory no patched version was available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-28: 109-28
Referenced assets1 URL
By indicator
Full discourse1 post
  • Rıdvan Yağlı@ridvanyagli

    🔴 Nezha'da kritik OAuth2 açığı — CVE-2026-101090 Nezha 2.2.3 sürümünde, dashboard_host yapılandırmasının boş olması durumunda Host Header Injection kaynaklı kritik bir güvenlik açığı tespit edildi. Saldırgan tarafından kontrol edilen Host header'ı, OAuth2 redirect_uri değerine yansıtılabiliyor. Uygun koşullarda OAuth authorization code saldırganın kontrolündeki adrese gönderilerek hesap ele geçirme mümkün olabiliyor. CVSS 3.1: 9.8 Critical CVSS 4.0: 9.3 Critical Etkilenen sürüm: Nezha 2.2.3 Nezha 2.2.3 kullanan sistemler en yeni sürüme güncellenmeli ve OAuth2 ve özellikle dashboard_host yapılandırması kontrol edilmeli. Advisory: https://github.com/nezhahq/nezha/security/advisories/GHSA-rf68-8gjr-36q7

    00000141
    2.4K followersView on X

Explore more