Information Disclosure in Nezha API for User Profiles
CVE-2026-101089

2.3LOW

Key Information:

Vendor

Nezhahq

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101089?

Nezha versions prior to 2.2.7 exhibit an information disclosure vulnerability within the GET /api/v1/profile endpoint. This flaw allows authenticated users’ bcrypt-hashed passwords to be exposed, enabling attackers to extract these password hashes. Once obtained, attackers can conduct offline cracking attacks without any rate limiting or audit trail constraints, significantly compromising user credentials and overall system security.

Affected Version(s)

nezha 0 < 2.2.7

nezha 2.2.7

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

de3erve-hunter
.