{"schema_version":1,"title":"NezhaHQ vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in NezhaHQ: 0 in the last 7 days and 1 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-59155, was published on 10 July 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/nezhahq","json_url":"https://junglewise.ai/threats/vendors/nezhahq.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/nezhahq","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":4,"all_time":16,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":16},"latest":[{"cve":"CVE-2026-59155","cvss":6.9,"slug":"cve-2026-59155-nezha-monitoring-plaintext-credential-exposure-in-ddns-and","title":"Nezha Monitoring plaintext credential exposure in DDNS and Notification APIs","severity":"info","exploited":false,"published_at":"2026-07-10T22:16:45.487+00:00","url":"https://junglewise.ai/threats/cve-2026-59155-nezha-monitoring-plaintext-credential-exposure-in-ddns-and"},{"cvss":5.5,"slug":"nezha-dashboard-credential-exposure-in-ddns-and-notification-apis-b3fe08f9","title":"Nezha Dashboard credential exposure in DDNS and Notification APIs","severity":"medium","exploited":false,"published_at":"2026-06-26T23:55:26+00:00","url":"https://junglewise.ai/threats/nezha-dashboard-credential-exposure-in-ddns-and-notification-apis-b3fe08f9"},{"cvss":9.9,"slug":"nezha-session-hijack-in-terminal-and-file-manager-via-websocket-uuid-89e25a74","title":"Nezha session hijack in terminal and file manager via WebSocket UUID","severity":"critical","exploited":false,"published_at":"2026-06-26T22:31:41+00:00","url":"https://junglewise.ai/threats/nezha-session-hijack-in-terminal-and-file-manager-via-websocket-uuid-89e25a74"},{"cve":"CVE-2026-53523","cvss":6.8,"epss":0.0023,"slug":"cve-2026-53523-nezha-monitoring-host-header-injection-in-oauth2-callback","title":"Nezha Monitoring Host Header Injection in OAuth2 callback","severity":"medium","exploited":false,"published_at":"2026-06-12T22:16:52.523+00:00","url":"https://junglewise.ai/threats/cve-2026-53523-nezha-monitoring-host-header-injection-in-oauth2-callback"},{"cve":"CVE-2026-53522","cvss":6.5,"epss":0.0029,"slug":"cve-2026-53522-nezha-monitoring-resource-exhaustion-via-unbounded-websocket","title":"Nezha Monitoring resource exhaustion via unbounded WebSocket streams","severity":"medium","exploited":false,"published_at":"2026-06-12T22:16:52.377+00:00","url":"https://junglewise.ai/threats/cve-2026-53522-nezha-monitoring-resource-exhaustion-via-unbounded-websocket"},{"cve":"CVE-2026-53521","cvss":6.4,"epss":0.0023,"slug":"cve-2026-53521-nezha-monitoring-authorization-bypass-in-ddns-profile-binding","title":"Nezha Monitoring authorization bypass in DDNS profile binding","severity":"medium","exploited":false,"published_at":"2026-06-12T22:16:52.23+00:00","url":"https://junglewise.ai/threats/cve-2026-53521-nezha-monitoring-authorization-bypass-in-ddns-profile-binding"},{"cve":"CVE-2026-53520","cvss":6.5,"epss":0.0028,"slug":"cve-2026-53520-nezha-monitoring-improper-access-control-in-nat-dashboard-routing","title":"Nezha Monitoring improper access control in NAT dashboard routing","severity":"medium","exploited":false,"published_at":"2026-06-12T22:16:52.097+00:00","url":"https://junglewise.ai/threats/cve-2026-53520-nezha-monitoring-improper-access-control-in-nat-dashboard-routing"},{"cve":"CVE-2026-53519","cvss":9.1,"epss":0.0045,"slug":"cve-2026-53519-nezha-monitoring-path-traversal-in-dashboard-noroute-handler","title":"Nezha Monitoring path traversal in dashboard NoRoute handler","severity":"critical","exploited":false,"published_at":"2026-06-12T22:16:51.953+00:00","url":"https://junglewise.ai/threats/cve-2026-53519-nezha-monitoring-path-traversal-in-dashboard-noroute-handler"},{"cve":"CVE-2026-49397","cvss":5.3,"epss":0.0003,"slug":"cve-2026-49397-nezha-monitoring-information-disclosure-in-service-endpoints","title":"Nezha Monitoring Information Disclosure in Service Endpoints","severity":"medium","exploited":false,"published_at":"2026-06-12T22:16:51.813+00:00","url":"https://junglewise.ai/threats/cve-2026-49397-nezha-monitoring-information-disclosure-in-service-endpoints"},{"cve":"CVE-2026-49396","cvss":7.1,"epss":0.0002,"slug":"cve-2026-49396-nezha-monitoring-csrf-in-cron-manual-trigger-endpoint","title":"Nezha Monitoring CSRF in cron manual-trigger endpoint","severity":"high","exploited":false,"published_at":"2026-06-12T22:16:51.677+00:00","url":"https://junglewise.ai/threats/cve-2026-49396-nezha-monitoring-csrf-in-cron-manual-trigger-endpoint"},{"cve":"CVE-2026-48119","cvss":7.1,"epss":0.0004,"slug":"cve-2026-48119-nezha-monitoring-authorization-bypass-in-service-monitor-result","title":"Nezha Monitoring authorization bypass in service-monitor result worker","severity":"high","exploited":false,"published_at":"2026-06-12T22:16:51.54+00:00","url":"https://junglewise.ai/threats/cve-2026-48119-nezha-monitoring-authorization-bypass-in-service-monitor-result"},{"cve":"CVE-2026-47268","cvss":6.4,"epss":0.0004,"slug":"cve-2026-47268-nezha-monitoring-ssrf-in-ddns-webhook-configuration","title":"Nezha Monitoring SSRF in DDNS webhook configuration","severity":"medium","exploited":false,"published_at":"2026-06-12T22:16:51.39+00:00","url":"https://junglewise.ai/threats/cve-2026-47268-nezha-monitoring-ssrf-in-ddns-webhook-configuration"},{"cve":"CVE-2026-47124","cvss":6.5,"epss":0.0006,"slug":"cve-2026-47124-nezha-monitoring-information-disclosure-in-server-status","title":"Nezha Monitoring Information Disclosure in Server-Status WebSocket","severity":"medium","exploited":false,"published_at":"2026-06-12T22:16:51.25+00:00","url":"https://junglewise.ai/threats/cve-2026-47124-nezha-monitoring-information-disclosure-in-server-status"},{"cve":"CVE-2026-47120","cvss":7.1,"epss":0.0004,"slug":"cve-2026-47120-nezha-monitoring-missing-authorization-in-alertrule-and-service","title":"Nezha Monitoring missing authorization in AlertRule and Service trigger tasks","severity":"high","exploited":false,"published_at":"2026-06-12T22:16:51.1+00:00","url":"https://junglewise.ai/threats/cve-2026-47120-nezha-monitoring-missing-authorization-in-alertrule-and-service"},{"cve":"CVE-2026-46717","cvss":8.5,"epss":0.0003,"slug":"cve-2026-46717-nezha-monitoring-ssrf-and-authorization-bypass-in-notification","title":"Nezha Monitoring SSRF and Authorization Bypass in Notification API","severity":"high","exploited":false,"published_at":"2026-06-12T22:16:50.957+00:00","url":"https://junglewise.ai/threats/cve-2026-46717-nezha-monitoring-ssrf-and-authorization-bypass-in-notification"},{"cve":"CVE-2026-46716","cvss":9.9,"epss":0.0005,"slug":"cve-2026-46716-nezha-monitoring-cross-tenant-rce-via-cron-task-api","title":"Nezha Monitoring Cross-Tenant RCE via Cron Task API","severity":"critical","exploited":false,"published_at":"2026-06-12T22:16:50.81+00:00","url":"https://junglewise.ai/threats/cve-2026-46716-nezha-monitoring-cross-tenant-rce-via-cron-task-api"}],"vendor":{"hub":true,"name":"NezhaHQ","slug":"nezhahq","homepage":"https://github.com/naiba/nezha","description":"NezhaHQ is an open-source software development organization focused on server monitoring and management tools.","url":"https://junglewise.ai/threats/vendors/nezhahq"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-46716","cvss":9.9,"epss":0.0005,"slug":"cve-2026-46716-nezha-monitoring-cross-tenant-rce-via-cron-task-api","title":"Nezha Monitoring Cross-Tenant RCE via Cron Task API","severity":"critical","exploited":false,"published_at":"2026-06-12T22:16:50.81+00:00","url":"https://junglewise.ai/threats/cve-2026-46716-nezha-monitoring-cross-tenant-rce-via-cron-task-api"},{"cvss":9.9,"slug":"nezha-session-hijack-in-terminal-and-file-manager-via-websocket-uuid-89e25a74","title":"Nezha session hijack in terminal and file manager via WebSocket UUID","severity":"critical","exploited":false,"published_at":"2026-06-26T22:31:41+00:00","url":"https://junglewise.ai/threats/nezha-session-hijack-in-terminal-and-file-manager-via-websocket-uuid-89e25a74"},{"cve":"CVE-2026-53519","cvss":9.1,"epss":0.0045,"slug":"cve-2026-53519-nezha-monitoring-path-traversal-in-dashboard-noroute-handler","title":"Nezha Monitoring path traversal in dashboard NoRoute handler","severity":"critical","exploited":false,"published_at":"2026-06-12T22:16:51.953+00:00","url":"https://junglewise.ai/threats/cve-2026-53519-nezha-monitoring-path-traversal-in-dashboard-noroute-handler"},{"cve":"CVE-2026-46717","cvss":8.5,"epss":0.0003,"slug":"cve-2026-46717-nezha-monitoring-ssrf-and-authorization-bypass-in-notification","title":"Nezha Monitoring SSRF and Authorization Bypass in Notification API","severity":"high","exploited":false,"published_at":"2026-06-12T22:16:50.957+00:00","url":"https://junglewise.ai/threats/cve-2026-46717-nezha-monitoring-ssrf-and-authorization-bypass-in-notification"},{"cve":"CVE-2026-48119","cvss":7.1,"epss":0.0004,"slug":"cve-2026-48119-nezha-monitoring-authorization-bypass-in-service-monitor-result","title":"Nezha Monitoring authorization bypass in service-monitor result worker","severity":"high","exploited":false,"published_at":"2026-06-12T22:16:51.54+00:00","url":"https://junglewise.ai/threats/cve-2026-48119-nezha-monitoring-authorization-bypass-in-service-monitor-result"},{"cve":"CVE-2026-47120","cvss":7.1,"epss":0.0004,"slug":"cve-2026-47120-nezha-monitoring-missing-authorization-in-alertrule-and-service","title":"Nezha Monitoring missing authorization in AlertRule and Service trigger tasks","severity":"high","exploited":false,"published_at":"2026-06-12T22:16:51.1+00:00","url":"https://junglewise.ai/threats/cve-2026-47120-nezha-monitoring-missing-authorization-in-alertrule-and-service"},{"cve":"CVE-2026-49396","cvss":7.1,"epss":0.0002,"slug":"cve-2026-49396-nezha-monitoring-csrf-in-cron-manual-trigger-endpoint","title":"Nezha Monitoring CSRF in cron manual-trigger endpoint","severity":"high","exploited":false,"published_at":"2026-06-12T22:16:51.677+00:00","url":"https://junglewise.ai/threats/cve-2026-49396-nezha-monitoring-csrf-in-cron-manual-trigger-endpoint"},{"cve":"CVE-2026-53523","cvss":6.8,"epss":0.0023,"slug":"cve-2026-53523-nezha-monitoring-host-header-injection-in-oauth2-callback","title":"Nezha Monitoring Host Header Injection in OAuth2 callback","severity":"medium","exploited":false,"published_at":"2026-06-12T22:16:52.523+00:00","url":"https://junglewise.ai/threats/cve-2026-53523-nezha-monitoring-host-header-injection-in-oauth2-callback"},{"cve":"CVE-2026-53522","cvss":6.5,"epss":0.0029,"slug":"cve-2026-53522-nezha-monitoring-resource-exhaustion-via-unbounded-websocket","title":"Nezha Monitoring resource exhaustion via unbounded WebSocket streams","severity":"medium","exploited":false,"published_at":"2026-06-12T22:16:52.377+00:00","url":"https://junglewise.ai/threats/cve-2026-53522-nezha-monitoring-resource-exhaustion-via-unbounded-websocket"},{"cve":"CVE-2026-53520","cvss":6.5,"epss":0.0028,"slug":"cve-2026-53520-nezha-monitoring-improper-access-control-in-nat-dashboard-routing","title":"Nezha Monitoring improper access control in NAT dashboard routing","severity":"medium","exploited":false,"published_at":"2026-06-12T22:16:52.097+00:00","url":"https://junglewise.ai/threats/cve-2026-53520-nezha-monitoring-improper-access-control-in-nat-dashboard-routing"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"NezhaHQ Nezha Monitoring","slug":"nezha","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/nezha"}]}