Sploitus

CVE-2026-46717

No indexed exploits for CVE-2026-46717 yet

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notification routes POST /api/v1/notification and PATCH /api/v1/notification/:id are wired through commonHandler rather than adminHandler β€” so a RoleMember user can call them. These handlers synchronously Send() an HTTP request to a user-controlled URL and reflect the entire response body (no size limit) back to the caller on any non-2xx response. This issue has been patched in version 2.0.8.

Affected products
Nezha Monitoring
Fix
Available
CVSS 3.1
7.7 HIGH
EPSS
0.3% (19th percentile)
Weakness
CWE-918, CWE-863
NVD status
Deferred
Published
2026-06-12
CVE-2026-46717 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-46717 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-46717 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows β€” not that no exploit exists.