OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-101090

CRITICAL · CVSS 9.8 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects Nezha 2.2.3, specifically in the OAuth2 redirect endpoint, where an empty dashboard_host setting allows for Host header injection. This flaw can enable an attacker to redirect a victim's OAuth2 authorization code to a malicious URL, potentially leading to account takeover. Organizations using this version of Nezha should prioritize immediate remediation, especially if they have not configured the dashboard_host setting.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101090
Severity
CRITICAL
CVSS
9.8
EPSS
0.36%

Original NVD Description

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to begin OAuth2 login via a request that reaches Nezha with a forged Host header can cause an attacker-controlled callback URL to be used as the redirect_uri; if the OAuth2 provider accepts it, the victim's authorization code is delivered to the attacker origin, allowing the attacker to complete the OAuth2 login/binding flow and take over the account. This regresses the fix for GHSA-9rc6-8cjv-rcvx and is configuration-dependent (dashboard_host empty). At the time of the advisory no patched version was available.