PT-2026-49004 · Nezhahq · Nezha

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-53523

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRedirectURL function in oauth2.go:22-29 constructs the OAuth2 callback URL by concatenating the request's Host header with a fixed path, with zero validation of the Host header. This can result in host header injection. This issue has been patched in version 2.2.0.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2026-53523

Affected Products

Nezha