CVE-2026-101087

MEDIUM CVSS 4.0: 5.3 EPSS 0.26%
Updated Sep 30, 2026
Nezha
Parameter Value
CVSS 5.3 (MEDIUM)
Affected Versions 2.0.10 — 2.3.2
Fixed In 2.3.3
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Nezha
Public PoC No

Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges — specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix 64:ff9b:1::/48. Because such addresses satisfy Go's netip.Addr.IsGlobalUnicast check, the URL validator accepted them. An authenticated user able to configure a webhook may be able to cause the dashboard to issue requests to an otherwise restricted IPv6 endpoint, but only where the dashboard's network provides unusual or non-standards-compliant routing for these transition ranges; no direct path to an IPv4 metadata, loopback, or private-network HTTP request has been demonstrated.

The issue is fixed in version 2.3.3 (commit d1fcde8e), which blocks both prefixes.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products

nezhahq:nezha