CVE-2026-101089: Nezhahq Nezha

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rate limiting or audit trail constraints.

Affected products

  • Nezhahq Nezha: before 2.2.7 (fixed in 2.2.7)

Published 2026-09-27. Last modified 2026-09-28.