PatchSiren cyber security CVE debrief
CVE-2026-101087 nezhahq CVE debrief
CVE-2026-101087 is a vulnerability in Nezha versions 2.0.10 through 2.3.2 that allows an authenticated user to bypass the denylist for webhook URLs, potentially causing the dashboard to issue requests to restricted IPv6 endpoints. The issue arises from the denylist not covering IPv6 transition ranges, specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix 64:ff9b:1::/48. This could lead to unauthorized requests if the dashboard's network provides unusual or non-standards-compliant routing for these transition ranges.
- Vendor
- nezhahq
- Product
- nezha
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-09-27
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-09-27
Who should care
Defenders and administrators of systems using Nezha versions 2.0.10 through 2.3.2 should assess exposure and apply the fix, especially in environments with non-standard IPv6 routing.
Why it matters
CVE-2026-101087 is a medium-severity vulnerability in Nezha that allows authenticated users to bypass webhook URL validation, potentially leading to requests to restricted IPv6 endpoints. Defenders should prioritize verifying exposure, applying the fix, and reviewing network routing.
- Potential for unauthorized requests to restricted IPv6 endpoints.
- Need for verification of exposure and application of the fix.
- Importance of reviewing network routing for IPv6 compliance.
- Monitoring for unusual requests to restricted endpoints.
Technical summary
The vulnerability arises from Nezha's restricted HTTP client not properly denylisting IPv6 transition ranges, allowing authenticated users to configure webhooks that may cause the dashboard to issue requests to restricted IPv6 endpoints. The denylist did not cover IPv6 transition ranges, specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix 64:ff9b:1::/48. This issue is fixed in version 2.3.3 (commit d1fcde8e), which blocks both prefixes. The fix ensures that the dashboard cannot issue requests to these restricted IPv6 endpoints, mitigating the vulnerability.
Defensive priority
Defenders should prioritize verifying exposure and applying the fix in version 2.3.3, especially for systems with unusual IPv6 routing.
Recommended defensive actions
- Verify if systems using Nezha versions 2.0.10 through 2.3.2 are exposed to potential IPv6 endpoint requests.
- Apply the fix in version 2.3.3 to block the affected prefixes.
- Review network routing for compliance with IPv6 standards.
- Monitor for unusual requests to restricted IPv6 endpoints.
- Perform a thorough review of network configurations to ensure compliance with IPv6 standards.
- Check for any existing compensating controls that may mitigate the vulnerability.
- Track the implementation of the fix and verify its effectiveness.
Evidence notes
The vulnerability arises from Nezha's restricted HTTP client not properly denylisting IPv6 transition ranges, specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix 64:ff9b:1::/48. The denylist did not cover these ranges, allowing authenticated users to configure webhooks that may cause the dashboard to issue requests to restricted IPv6 endpoints. This issue is fixed in version 2.3.3 (commit d1fcde8e), which blocks both prefixes. Evidence is based on the CVE record and Nezha's security advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-101087 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-101087
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-101087 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-101087
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/nezhahq/nezha/commit/d1fcde8e
-
Source reference
Unverified legacy reference
URL: https://github.com/nezhahq/nezha/security/advisories/GHSA-jr2j-7hvh-h4q9
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/nezha-2.0.10-through-2.3.2-ssrf-denylist-bypass-ipv6
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.