CVE-2026-101090 is a critical Host header injection regression in Nezha 2.2.3's OAuth2 redirect endpoint that can let an attacker steal a victim's authorization code and take over their account.
What Is It
The flaw is in Nezha's OAuth2 redirect endpoint, /api/v1/oauth2/{provider}, implemented in cmd/dashboard/controller/oauth2.go. Nezha 2.2.3 added an optional dashboard_host setting. When that setting is left empty, the endpoint puts the attacker-supplied HTTP Host header into the redirect_uri it sends to the identity provider. It should fall back to the configured install_host instead.
An attacker can get a victim to start an OAuth2 login through a request that reaches Nezha with a forged Host header. That makes an attacker-controlled callback URL the redirect_uri. If the OAuth2 provider accepts that URL, the victim's authorization code goes to the attacker's origin. The attacker can then complete the OAuth2 login or binding flow and take over the account.
The issue is a regression of the earlier fix for GHSA-9rc6-8cjv-rcvx. It is classified as CWE-601 (URL Redirection to Untrusted Site, "Open Redirect").
Why It Matters
- CVSS 3.1: 9.8 (CRITICAL), vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0: 9.3 (CRITICAL)
A successful attack ends in full account takeover of the Nezha dashboard. Because this is a regression, deployments that were protected by the earlier fix may be exposed again after upgrading to 2.2.3.
Scoring caveat: The CVSS 3.1 vector rates attack complexity as low (AC:L) and says no user interaction is needed (UI:N). The attack the advisory describes does not fully match that rating. A victim has to start an OAuth2 login through the attacker-influenced request, the target has to run with an empty dashboard_host, and the OAuth2 provider has to accept the attacker-controlled callback URL. Defenders should treat the 9.8 score as the published rating. The real-world exploitability of a given deployment depends on these preconditions.
Exploitation status: No CISA Known Exploited Vulnerabilities (KEV) entry was provided for this CVE. Active exploitation is not confirmed by KEV at this time. The NVD record has the status "Received" and has not yet been fully analyzed.
What's Vulnerable
- Vendor/Product: nezhahq / nezha
- Package:
pkg:golang/github.com/nezhahq/nezha - Affected versions: 2.2.3 (listed as
lessThanOrEqual: 2.2.3) - Configuration dependency: Only exploitable when
dashboard_hostis empty. - Additional condition: The OAuth2 identity provider must accept the attacker-controlled callback URL as the
redirect_uri. - User interaction: A victim must start the OAuth2 login flow through the attacker-influenced request.
Patch Status
According to the advisory, no patched version was available when it was published. Neither the NVD record nor a KEV entry lists a required remediation action.
Based on the configuration dependency described in the advisory, the condition that triggers the bug is an empty dashboard_host. Administrators should:
- check whether their deployments leave that value unset
- check which redirect URIs their OAuth2 providers accept
- watch the vendor advisory for a fixed release