Long-lived WebSocket Stream Vulnerability in Nezha Monitoring Tool by Nezha
CVE-2026-53522

6.5MEDIUM

Key Information:

Vendor

Nezhahq

Status
Vendor
CVE Published:
12 June 2026

What is CVE-2026-53522?

Nezha Monitoring, a self-hostable tool for monitoring servers and websites, is affected by a vulnerability that allows the creation of long-lived WebSocket streams without proper user and connection limits. The issue arises from the dashboard's handling of WebSocket connection endpoints, specifically POST requests that create terminal and file streams. The absence of a rate limit and connection cap may lead to potential abuse or denial-of-service attacks, compromising the functionality and performance of the monitoring tool. This vulnerability has been addressed in version 2.2.0.

Affected Version(s)

nezha >= 1.0.0, < 2.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.