CVE-2026-101090
Received Received - Intake

Host Header Injection in Nezha OAuth2 Redirect

Vulnerability report for CVE-2026-101090, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to begin OAuth2 login via a request that reaches Nezha with a forged Host header can cause an attacker-controlled callback URL to be used as the redirect_uri; if the OAuth2 provider accepts it, the victim's authorization code is delivered to the attacker origin, allowing the attacker to complete the OAuth2 login/binding flow and take over the account. This regresses the fix for GHSA-9rc6-8cjv-rcvx and is configuration-dependent (dashboard_host empty). At the time of the advisory no patched version was available.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nezha nezha to 2.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Nezha 2.2.3 has a Host header injection issue in its OAuth2 redirect endpoint. When a specific setting is empty, the system uses an attacker-controlled Host header to generate a redirect URL for OAuth2 login. This allows an attacker to trick users into sending their authorization codes to a malicious site, potentially taking over their accounts.

Detection Guidance

This vulnerability is specific to Nezha 2.2.3 with a misconfigured dashboard_host setting. To detect it, inspect the OAuth2 redirect endpoint /api/v1/oauth2/{provider} for Host header injection by checking if the redirect_uri includes an attacker-controlled Host header when dashboard_host is empty.

Impact Analysis

If you use Nezha 2.2.3 with the vulnerable configuration, an attacker could hijack your OAuth2 login session. This means they might gain access to your account, steal data, or perform actions on your behalf without your consent.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches, loss of confidentiality, and non-compliance with regulatory obligations.

Mitigation Strategies

Immediately upgrade Nezha to a patched version if available. If no patch exists, set the dashboard_host configuration to a trusted host to prevent Host header injection. Disable OAuth2 login temporarily if possible until the issue is resolved.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101090. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart