CVE-2026-53520

Source
https://cve.org/CVERecord?id=CVE-2026-53520
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53520.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53520
Aliases
Downstream
Related
Published
2026-06-12T21:03:58.782Z
Modified
2026-07-31T18:31:46.309398908Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
Details

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing. This issue has been patched in version 2.1.0.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53520.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nezhahq/nezha

Affected ranges

Type
GIT
Repo
https://github.com/nezhahq/nezha
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "2.0.14"
        },
        {
            "fixed": "2.1.0"
        },
        {
            "introduced": "0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53520.json"