Package impact

golang Go / github.com/nezhahq/nezha

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-46717 high 8.0 8d ago Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
CVE-2026-47124 medium 5.5 8d ago Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members
CVE-2026-47120 medium 5.5 8d ago Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)
CVE-2026-47268 unknown 15h ago Nezha's authenticated DDNS webhook configuration allows blind SSRF from the dashboard host