CVE-2026-101090: URL Redirection to Untrusted Site ('Open Redirect') in nezhahq nezha
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to begin OAuth2 login via a request that reaches Nezha with a forged Host header can cause an attacker-controlled callback URL to be used as the redirect_uri; if the OAuth2 provider accepts it, the victim's authorization code is delivered to the attacker origin, allowing the attacker to complete the OAuth2 login/binding flow and take over the account. This regresses the fix for GHSA-9rc6-8cjv-rcvx and is configuration-dependent (dashboard_host empty). At the time of the advisory no patched version was available.
AI Analysis
Technical Summary
CVE-2026-101090 affects Nezha version 2.2.3 and involves a Host header injection regression in the OAuth2 redirect endpoint (/api/v1/oauth2/{provider}). When the dashboard_host setting is empty, the application uses the HTTP Host header from the request to build the redirect_uri sent to the OAuth2 provider instead of the configured install_host. An attacker can exploit this by inducing a victim to initiate an OAuth2 login with a forged Host header, causing the victim's authorization code to be redirected to an attacker-controlled URL. This allows the attacker to complete the OAuth2 login or binding flow and take over the victim's account. This vulnerability reintroduces a previously fixed issue (GHSA-9rc6-8cjv-rcvx) and depends on the dashboard_host configuration. No official fix or patch was available at the time of publication.
Potential Impact
Successful exploitation allows an attacker to hijack the OAuth2 login flow by redirecting the victim's authorization code to an attacker-controlled URL. This can lead to account takeover without requiring user interaction beyond initiating the login process. The vulnerability is critical due to its ability to bypass authentication controls and compromise user accounts.
Mitigation Recommendations
At the time of the advisory, no patch or official fix was available. The vulnerability is configuration-dependent; setting the dashboard_host configuration to a non-empty, trusted value may mitigate the issue by preventing the use of the attacker-supplied Host header in the redirect_uri. Users should monitor the vendor's advisory for updates and apply any future patches promptly.
CVE-2026-101090: URL Redirection to Untrusted Site ('Open Redirect') in nezhahq nezha
Description
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to begin OAuth2 login via a request that reaches Nezha with a forged Host header can cause an attacker-controlled callback URL to be used as the redirect_uri; if the OAuth2 provider accepts it, the victim's authorization code is delivered to the attacker origin, allowing the attacker to complete the OAuth2 login/binding flow and take over the account. This regresses the fix for GHSA-9rc6-8cjv-rcvx and is configuration-dependent (dashboard_host empty). At the time of the advisory no patched version was available.
CVSS v4.0
Score 9.3critical
Affected software
nezhahq
nezha
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-101090 affects Nezha version 2.2.3 and involves a Host header injection regression in the OAuth2 redirect endpoint (/api/v1/oauth2/{provider}). When the dashboard_host setting is empty, the application uses the HTTP Host header from the request to build the redirect_uri sent to the OAuth2 provider instead of the configured install_host. An attacker can exploit this by inducing a victim to initiate an OAuth2 login with a forged Host header, causing the victim's authorization code to be redirected to an attacker-controlled URL. This allows the attacker to complete the OAuth2 login or binding flow and take over the victim's account. This vulnerability reintroduces a previously fixed issue (GHSA-9rc6-8cjv-rcvx) and depends on the dashboard_host configuration. No official fix or patch was available at the time of publication.
Potential Impact
Successful exploitation allows an attacker to hijack the OAuth2 login flow by redirecting the victim's authorization code to an attacker-controlled URL. This can lead to account takeover without requiring user interaction beyond initiating the login process. The vulnerability is critical due to its ability to bypass authentication controls and compromise user accounts.
Mitigation Recommendations
At the time of the advisory, no patch or official fix was available. The vulnerability is configuration-dependent; setting the dashboard_host configuration to a non-empty, trusted value may mitigate the issue by preventing the use of the attacker-supplied Host header in the redirect_uri. Users should monitor the vendor's advisory for updates and apply any future patches promptly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-27T20:29:07.433Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab98495f7a7c541067b9772
Added to database: 09/27/2026, 21:03:17 UTC
Last enriched: 09/27/2026, 21:17:42 UTC
Last updated: 09/28/2026, 02:17:12 UTC
Views: 28
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.