Tor to the World · story 1598 · official · 1 source(s)

CVE-2026-101090: Critical Host Header Injection in Nezha

Nezha version 2.2.3 contains a host header injection vulnerability in the OAuth2 redirect endpoint allowing attackers to manipulate redirect URIs.

Open in the desk

Coverage

What this site indexes