<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T07:42:02.937635+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-327418</id>
    <title>EUVD-2026-327418</title>
    <updated>2026-10-06T07:42:02.992460+00:00</updated>
    <content>EUVD-2026-327418</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-327418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53523</id>
    <title>fkie_cve-2026-53523</title>
    <updated>2026-10-06T07:42:02.992506+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&amp;M tool. From version 1.0.0 to before version 2.2.0, the getRedirectURL function in oauth2.go:22-29 constructs the OAuth2 callback URL by concatenating the request's Host header with a fixed path, with zero validation of the Host header. This can result in host header injection. This issue has been patched in version 2.2.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53523"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9rc6-8cjv-rcvx</id>
    <title>GHSA-9rc6-8cjv-rcvx — Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection</title>
    <updated>2026-10-06T07:42:02.992603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/nezhahq/nezha</p>
<p>## 1. Description</p>
<p>The `getRedirectURL` function in `oauth2.go:22-29` constructs the OAuth2 callback URL by concatenating the request's `Host` header with a fixed path, with **zero validation** of the Host header:</p>
<p>```go
func getRedirectURL(c *gin.Context) string {
    scheme := "http://"
    referer := c.Request.Referer()
    if forwardedProto := c.Request.Header.Get("X-Forwarded-Proto"); forwardedProto == "https" || strings.HasPrefix(referer, "https://") {
        scheme = "https://"
    }
    return scheme + c.Request.Host + "/api/v1/oauth2/callback"
}
```</p>
<p>**File:** `cmd/dashboard/controller/oauth2.go:22-29`</p>
<p>This function is called from `oauth2redirect()` at line 53:
```go
func oauth2redirect(c *gin.Context) (*model.Oauth2LoginResponse, error) {
    // ...
    redirectURL := getRedirectURL(c)
    o2conf := o2confRaw.Setup(redirectURL)
    // ...
    url := o2conf.AuthCodeURL(state, oauth2.AccessTypeOnline)
    return &amp;model.Oauth2LoginResponse{Redirect: url}, nil
}
```</p>
<p>The `redirectURL` is passed into `o2confRaw.Setup(redirectURL)` which configures the OAuth2 `Config.RedirectURL` field (`oauth2config.go:22-33`). This `RedirectURL` is sent to the OAuth2 provider (e.g., GitHub, Google, Microsoft) as the callback endpoint. The OAuth2 provider will redirect the user's browser — along with the authorization code — to this URL after the user authenticates.</p>
<p>The security issue is that `c.Request.Host` is directly user-controllable via the HTTP `Host` header. An attacker who c…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9rc6-8cjv-rcvx"/>
  </entry>
</feed>
