Long-lived WebSocket Stream Vulnerability in Nezha Monitoring Tool by Nezha
CVE-2026-53522
6.5MEDIUM
What is CVE-2026-53522?
Nezha Monitoring, a self-hostable tool for monitoring servers and websites, is affected by a vulnerability that allows the creation of long-lived WebSocket streams without proper user and connection limits. The issue arises from the dashboard's handling of WebSocket connection endpoints, specifically POST requests that create terminal and file streams. The absence of a rate limit and connection cap may lead to potential abuse or denial-of-service attacks, compromising the functionality and performance of the monitoring tool. This vulnerability has been addressed in version 2.2.0.
Affected Version(s)
nezha >= 1.0.0, < 2.2.0
