SSRF Vulnerability in Nezha Versions by Nezha
CVE-2026-101087
5.3MEDIUM
What is CVE-2026-101087?
In Nezha versions 2.0.10 to 2.3.2, a vulnerability exists that allows an authenticated user to bypass restricted HTTP client validations for user-configurable webhook URLs. This occurs due to the improper handling of specific IPv6 prefix ranges (2002::/16 and 64:ff9b:1::/48) that are not included in the denylist. While the security check ensures that URLs are validated against a global unicast standard, it incorrectly accepts these transition addresses, which could lead to unauthorized requests being made by the dashboard under suitable network conditions. The issue was addressed in version 2.3.3 with a patch that appropriately blocks these prefixes.
Affected Version(s)
nezha 2.0.10 < 2.3.3
nezha 2.3.3
