PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-101087 nezhahq CVE debrief

CVE-2026-101087 is a vulnerability in Nezha versions 2.0.10 through 2.3.2 that allows an authenticated user to bypass the denylist for webhook URLs, potentially causing the dashboard to issue requests to restricted IPv6 endpoints. The issue arises from the denylist not covering IPv6 transition ranges, specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix 64:ff9b:1::/48. This could lead to unauthorized requests if the dashboard's network provides unusual or non-standards-compliant routing for these transition ranges.

Vendor
nezhahq
Product
nezha
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-27
Original CVE updated
2026-09-27
Advisory published
2026-09-27
Advisory updated
2026-09-27

Who should care

Defenders and administrators of systems using Nezha versions 2.0.10 through 2.3.2 should assess exposure and apply the fix, especially in environments with non-standard IPv6 routing.

Why it matters

CVE-2026-101087 is a medium-severity vulnerability in Nezha that allows authenticated users to bypass webhook URL validation, potentially leading to requests to restricted IPv6 endpoints. Defenders should prioritize verifying exposure, applying the fix, and reviewing network routing.

  • Potential for unauthorized requests to restricted IPv6 endpoints.
  • Need for verification of exposure and application of the fix.
  • Importance of reviewing network routing for IPv6 compliance.
  • Monitoring for unusual requests to restricted endpoints.

Technical summary

The vulnerability arises from Nezha's restricted HTTP client not properly denylisting IPv6 transition ranges, allowing authenticated users to configure webhooks that may cause the dashboard to issue requests to restricted IPv6 endpoints. The denylist did not cover IPv6 transition ranges, specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix 64:ff9b:1::/48. This issue is fixed in version 2.3.3 (commit d1fcde8e), which blocks both prefixes. The fix ensures that the dashboard cannot issue requests to these restricted IPv6 endpoints, mitigating the vulnerability.

Defensive priority

Defenders should prioritize verifying exposure and applying the fix in version 2.3.3, especially for systems with unusual IPv6 routing.

Recommended defensive actions

  • Verify if systems using Nezha versions 2.0.10 through 2.3.2 are exposed to potential IPv6 endpoint requests.
  • Apply the fix in version 2.3.3 to block the affected prefixes.
  • Review network routing for compliance with IPv6 standards.
  • Monitor for unusual requests to restricted IPv6 endpoints.
  • Perform a thorough review of network configurations to ensure compliance with IPv6 standards.
  • Check for any existing compensating controls that may mitigate the vulnerability.
  • Track the implementation of the fix and verify its effectiveness.

Evidence notes

The vulnerability arises from Nezha's restricted HTTP client not properly denylisting IPv6 transition ranges, specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 translation prefix 64:ff9b:1::/48. The denylist did not cover these ranges, allowing authenticated users to configure webhooks that may cause the dashboard to issue requests to restricted IPv6 endpoints. This issue is fixed in version 2.3.3 (commit d1fcde8e), which blocks both prefixes. Evidence is based on the CVE record and Nezha's security advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-101087 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-101087

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-101087 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-101087

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.