Skip to main content

CVE-2026-101090: URL Redirection to Untrusted Site ('Open Redirect') in nezhahq nezha

0
Critical
VulnerabilityCVE-2026-101090cvecve-2026-101090
Published: 09/27/2026 (09/27/2026, 20:50:00 UTC)
Source: CVE Database V5
Vendor/Project: nezhahq
Product: nezha

Description

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to begin OAuth2 login via a request that reaches Nezha with a forged Host header can cause an attacker-controlled callback URL to be used as the redirect_uri; if the OAuth2 provider accepts it, the victim's authorization code is delivered to the attacker origin, allowing the attacker to complete the OAuth2 login/binding flow and take over the account. This regresses the fix for GHSA-9rc6-8cjv-rcvx and is configuration-dependent (dashboard_host empty). At the time of the advisory no patched version was available.

CVSS v4.0

Score 9.3critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

nezhahq

nezha

Affected versions
>=2.2.3 <=2.2.3
GitHub Actionsmore threats →ai
nezhahq/nezha
pkg:github/nezhahq/nezha
Affected versions
>=2.2.3 <=2.2.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/27/2026, 21:17:42 UTC

Technical Analysis

CVE-2026-101090 affects Nezha version 2.2.3 and involves a Host header injection regression in the OAuth2 redirect endpoint (/api/v1/oauth2/{provider}). When the dashboard_host setting is empty, the application uses the HTTP Host header from the request to build the redirect_uri sent to the OAuth2 provider instead of the configured install_host. An attacker can exploit this by inducing a victim to initiate an OAuth2 login with a forged Host header, causing the victim's authorization code to be redirected to an attacker-controlled URL. This allows the attacker to complete the OAuth2 login or binding flow and take over the victim's account. This vulnerability reintroduces a previously fixed issue (GHSA-9rc6-8cjv-rcvx) and depends on the dashboard_host configuration. No official fix or patch was available at the time of publication.

Potential Impact

Successful exploitation allows an attacker to hijack the OAuth2 login flow by redirecting the victim's authorization code to an attacker-controlled URL. This can lead to account takeover without requiring user interaction beyond initiating the login process. The vulnerability is critical due to its ability to bypass authentication controls and compromise user accounts.

Mitigation Recommendations

At the time of the advisory, no patch or official fix was available. The vulnerability is configuration-dependent; setting the dashboard_host configuration to a non-empty, trusted value may mitigate the issue by preventing the use of the attacker-supplied Host header in the redirect_uri. Users should monitor the vendor's advisory for updates and apply any future patches promptly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-27T20:29:07.433Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab98495f7a7c541067b9772

Added to database: 09/27/2026, 21:03:17 UTC

Last enriched: 09/27/2026, 21:17:42 UTC

Last updated: 09/28/2026, 02:17:12 UTC

Views: 28

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses