THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rf68-8gjr-36q7 (low) — Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

[GHSA] GHSA-rf68-8gjr-36q7 (low) — Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

highgithub_advisoriesPublished 2026-09-15

GHSA-rf68-8gjr-36q7 Severity: low CVE: None

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

## Summary

Nezha v2.2.3 regresses the GHSA-9rc6-8cjv-rcvx host header injection fix for deployments where the new `dashboard_host` setting is empty. In that configuration, `/api/v1/oauth2/{provider}` again reflects the request `Host` header into the OAuth2 `redire

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rf68-8gjr-36q7