Host Header Injection in Nezha 2.2.3 OAuth2 Redirect Endpoint
CVE-2026-101090

9.3CRITICAL

Key Information:

Vendor

Nezhahq

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101090?

Nezha version 2.2.3 is affected by a Host header injection vulnerability occurring in the OAuth2 redirect endpoint. This issue arises specifically when the optional 'dashboard_host' setting is left empty, leading the system to reflect the attacker-supplied HTTP Host header in the 'redirect_uri' sent to the identity provider. If successful, an attacker can manipulate a victim into initiating an OAuth2 login, resulting in the victim's authorization code being forwarded to an attacker-controlled callback URL. This flaw not only reinstates a previously resolved vulnerability but also relies on the specific configuration of the dashboard settings. Currently, there is no patched version available for this vulnerability.

Affected Version(s)

nezha 2.2.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DavidCarliez
.