Nezha
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 9 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 12, 2026 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri
Nezha before 2.2.7 Information Disclosure via /api/v1/profile
Nezha before 2.3.1 Denial of Service via Concurrent Server Delete
Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6
Nezha Dashboard before 2.3.5 Task Type Validation Bypass
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
Monitor Nezha in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.