CVE-2026-53523
Last modified
CVE-2026-53523 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRedirectURL function in oauth2.go:22-29 constructs the OAuth2 callback URL by concatenating the request's Host header with a fixed path, with zero validation of the Host header. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRedirectURL function in oauth2.go:22-29 constructs the OAuth2 callback URL by concatenating the request's Host header with a fixed path, with zero validation of the Host header. This can result in host header injection. This issue has been patched in version 2.2.0.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-53523?
How severe is CVE-2026-53523?
How do I fix CVE-2026-53523?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53518Better Auth is an authentication and authorization library f…8.1
- CVE-2026-53519Nezha Monitoring is a self-hostable, lightweight, servers an…9.1
- CVE-2026-5352A security vulnerability has been detected in Trendnet TEW-6…8.8
- CVE-2026-53520Nezha Monitoring is a self-hostable, lightweight, servers an…6.5
- CVE-2026-53521Nezha Monitoring is a self-hostable, lightweight, servers an…6.4
- CVE-2026-53522Nezha Monitoring is a self-hostable, lightweight, servers an…6.5
- CVE-2026-53524WeeChat (Wee Enhanced Environment for Chat) is a free chat c…6.5
- CVE-2026-53525WeeChat (Wee Enhanced Environment for Chat) is a free chat c…7.4
- CVE-2026-53527LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.…8.8
- CVE-2026-53528LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.…8.8
- CVE-2026-53529LeafWiki is a self-hosted wiki. Prior to version 0.10.2, pag…4.8
- CVE-2026-5353A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. …8.8
Are you affected by CVE-2026-53523?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
