CVE-2026-101089: Nezha before 2.2.7 Information Disclosure via /api/v1/profile
Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rate limiting or audit trail constraints.
Affected Software
Event History
Frequently Asked Questions
Who can retrieve the exposed password hashes?
An authenticated user can access the GET /api/v1/profile endpoint and retrieve the bcrypt-hashed password field. Exploitation requires a valid account with the necessary authenticated access.
What is the practical impact of the disclosure?
An attacker can collect password hashes and attempt to crack them offline. The described endpoint has no rate-limiting or audit-trail constraints for this extraction.
Which deployments are affected?
Nezha versions before 2.2.7 are affected. The provided information does not identify any configuration prerequisite beyond authenticated access.