VYPR

Nezha

by Nezhahq

Source repositories

CVEs (23)

  • CVE-2026-101087MedSep 27, 2026
    risk 0.21cvss 4.3epss 0.00

    Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges — specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix…

  • CVE-2026-101089LowSep 27, 2026
    risk 0.13cvss 3.1epss 0.00

    Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rate limiting or audit…

  • CVE-2026-59155MedJul 10, 2026
    risk 0.00cvss —epss 0.00

    Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API credentials, including Cloudflare API…

Page 2 of 2