CVE-2026-101087
Received Received - Intake

Nezha Dashboard IPv6 Transition Range URL Validation Bypass

Vulnerability report for CVE-2026-101087, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges β€” specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix 64:ff9b:1::/48. Because such addresses satisfy Go's netip.Addr.IsGlobalUnicast check, the URL validator accepted them. An authenticated user able to configure a webhook may be able to cause the dashboard to issue requests to an otherwise restricted IPv6 endpoint, but only where the dashboard's network provides unusual or non-standards-compliant routing for these transition ranges; no direct path to an IPv4 metadata, loopback, or private-network HTTP request has been demonstrated. The issue is fixed in version 2.3.3 (commit d1fcde8e), which blocks both prefixes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nezha nezha From 2.0.10 (inc) to 2.3.2 (inc)
nezha nezha 2.3.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Nezha versions 2.0.10 through 2.3.2 have a vulnerability where the HTTP client used to validate notification and DDNS webhook URLs does not properly block IPv6 transition ranges like 2002::/16 and 64:ff9b:1::/48. This allows authenticated users to configure webhooks that could send requests to restricted IPv6 endpoints, though exploitation requires non-standard network routing.

Detection Guidance

Check Nezha dashboard versions between 2.0.10 and 2.3.2 for the affected IPv6 transition ranges in webhook configurations. Inspect network logs for outbound requests to 2002::/16 or 64:ff9b:1::/48 prefixes.

Impact Analysis

An authenticated user could exploit this to make the dashboard send requests to unintended IPv6 endpoints, potentially bypassing network restrictions. However, this requires unusual network routing and does not directly enable access to metadata, loopback, or private networks.

Compliance Impact

This vulnerability does not directly impact compliance with standards like GDPR or HIPAA as it involves restricted IPv6 transition ranges and does not demonstrate a path to restricted endpoints such as loopback or private networks. The issue is limited to unusual network routing scenarios.

Mitigation Strategies

Upgrade Nezha to version 2.3.3 or later to block the vulnerable IPv6 prefixes. Review and restrict webhook configurations to prevent unauthorized IPv6 transitions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101087. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart