External risk intelligence

Nezha OAuth2 Host Header Injection Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-101090

The vulnerability resides in an OAuth2 authentication endpoint within a dashboard service. Such services are typically exposed to the internet to facilitate remote user authentication and login flows, making the endpoint publicly accessible by design.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a security regression in Nezha's OAuth2 redirect functionality, specifically when a particular setting is not configured. If exploited, an attacker could manipulate the redirect process during login to gain unauthorized account access. The main concern is confirming whether your deployment of Nezha is affected and to what extent.

  • A login process flaw can allow account takeover.
  • Understand the risk to user authentication.
  • Assess Nezha's configuration for potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by tricking a user into initiating an OAuth2 login. This requires the vulnerable Nezha service to be configured with an empty `dashboard_host` setting. The attacker crafts a malicious request with a forged `Host` header, which the service then includes in the redirect URI sent to the identity provider. If successful, the attacker receives the user's authorization code, enabling account takeover.

  • No special access needed.
  • User initiates OAuth2 login.
  • Account takeover and unauthorized access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to redirect users to an attacker-controlled URL during the OAuth2 login process. When the dashboard_host setting is not configured, a forged Host header can manipulate the redirect_uri. If the identity provider accepts this forged URL, an attacker could intercept the user's authorization code, enabling them to take over the user's account by completing the OAuth2 flow.

  • User account takeover.
  • Exploits an OAuth2 redirect flaw.
  • Compromises user account access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Security teams and potentially the Nezha application owners are responsible for addressing this Host header injection vulnerability. The first practical step is to identify all instances of Nezha, determine their external reachability and business criticality, and then locate the accountable system owners. Remediation planning should be based on this risk assessment, especially since a patched version is not yet available.

  • Identify Nezha instances and ownership.
  • Verify external reachability and criticality.
  • Plan remediation based on discovered risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Nezha?

Nezha is an open-source server monitoring and dashboard platform. It is commonly used by administrators to manage and track the health, uptime, and performance metrics of multiple servers through a centralized, web-based interface.

How does this CVE-2026-101090 vulnerability work?

This is a Host header injection, categorized as CWE-601. The software incorrectly uses the HTTP Host header from a web request to build an OAuth2 redirect URL. By forging this header, an attacker can trick the system into sending a user to an unauthorized destination during login.

What triggers this vulnerability in Nezha?

The flaw triggers only when the optional 'dashboard_host' setting is left empty. If this setting is configured correctly, the system uses it as the intended host, preventing the injection. It does not occur when 'dashboard_host' is explicitly defined.

Is my Nezha instance relevant to this threat?

Nezha dashboard services are typically exposed to the internet to allow remote authentication, making them prime targets. According to Halo Surface Signal, because this endpoint is designed to be publicly accessible for login flows, your instance is likely relevant if the vulnerable configuration is active.

What can I do if no patch is available?

Since there is no fix yet, you should immediately check your configuration files to see if 'dashboard_host' is empty. If it is, explicitly define a value for that setting to override the default behavior and close the injection path until an official update is released.

References