Information Disclosure in Nezha API for User Profiles
CVE-2026-101089
2.3LOW
What is CVE-2026-101089?
Nezha versions prior to 2.2.7 exhibit an information disclosure vulnerability within the GET /api/v1/profile endpoint. This flaw allows authenticated users’ bcrypt-hashed passwords to be exposed, enabling attackers to extract these password hashes. Once obtained, attackers can conduct offline cracking attacks without any rate limiting or audit trail constraints, significantly compromising user credentials and overall system security.
Affected Version(s)
nezha 0 < 2.2.7
nezha 2.2.7
