Host Header Injection in Nezha 2.2.3 OAuth2 Redirect Endpoint
CVE-2026-101090
9.3CRITICAL
What is CVE-2026-101090?
Nezha version 2.2.3 is affected by a Host header injection vulnerability occurring in the OAuth2 redirect endpoint. This issue arises specifically when the optional 'dashboard_host' setting is left empty, leading the system to reflect the attacker-supplied HTTP Host header in the 'redirect_uri' sent to the identity provider. If successful, an attacker can manipulate a victim into initiating an OAuth2 login, resulting in the victim's authorization code being forwarded to an attacker-controlled callback URL. This flaw not only reinstates a previously resolved vulnerability but also relies on the specific configuration of the dashboard settings. Currently, there is no patched version available for this vulnerability.
Affected Version(s)
nezha 2.2.3
