Sensitive Data Exposure in Nezha Monitoring by NezhaHQ
CVE-2026-59155
6.9MEDIUM
What is CVE-2026-59155?
Nezha Monitoring prior to version 2.2.5 has a vulnerability that allows authenticated users to access sensitive API credentials through unsecured endpoints. Specifically, the GET /api/v1/ddns and GET /api/v1/notification endpoints return complete resource objects that include plaintext third-party API credentials such as Cloudflare API tokens, TencentCloud SecretKeys, and various webhook URLs with embedded bot tokens and authorization headers. This lack of field-level redaction poses a significant security risk, as any authenticated admin or user with appropriate permissions can retrieve sensitive information in a single API response. The issue has been addressed in version 2.2.5.
Affected Version(s)
nezha < 2.2.5
