Sensitive Data Exposure in Nezha Monitoring by NezhaHQ
CVE-2026-59155

6.9MEDIUM

Key Information:

Vendor

Nezhahq

Status
Vendor
CVE Published:
10 July 2026

What is CVE-2026-59155?

Nezha Monitoring prior to version 2.2.5 has a vulnerability that allows authenticated users to access sensitive API credentials through unsecured endpoints. Specifically, the GET /api/v1/ddns and GET /api/v1/notification endpoints return complete resource objects that include plaintext third-party API credentials such as Cloudflare API tokens, TencentCloud SecretKeys, and various webhook URLs with embedded bot tokens and authorization headers. This lack of field-level redaction poses a significant security risk, as any authenticated admin or user with appropriate permissions can retrieve sensitive information in a single API response. The issue has been addressed in version 2.2.5.

Affected Version(s)

nezha < 2.2.5

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.