Sceawere
Vulnerability Detail
CVE-2026-101089UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Nezha Unauthorized Password Hash Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.1
- Creation Date
- 11h ago
- Vendor
- nezhahq
- Product
- nezha
- Attack Type
- Insufficiently Protected Credentials
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rate limiting or audit trail constraints.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.1",
"pubDate": "2026-09-27T21:17:02.870Z",
"pubdate": "2026-09-27T21:17:02.870Z",
"executiveSummary": "Nezha versions prior to 2.2.7 are susceptible to an information disclosure vulnerability within the /api/v1/profile endpoint.\nThe vulnerability involves the improper inclusion of sensitive user account credentials, specifically bcrypt-hashed passwords, in API response objects.\nThis flaw allows authenticated users to retrieve password hashes belonging to account profiles without appropriate authorization checks or system constraints.\nThe primary risk entails the potential for offline brute-force or dictionary-based password cracking attacks, which could lead to unauthorized account takeover.\nBecause the vulnerability exists in an API endpoint lacking rate limiting or robust audit logging, malicious actors can perform reconnaissance and data extraction with minimal risk of detection.\nThe lack of field filtering on the /api/v1/profile endpoint exposes internal credential management, violating the principle of least privilege regarding data exposure.\nOrganizations relying on Nezha are at risk of credential compromise if defensive measures or patch updates are not prioritized immediately.",
"technicalDetails": "The vulnerability resides in the GET /api/v1/profile endpoint of the Nezha application, which is responsible for returning user profile information. The root cause is a failure to implement field-level sanitization on the user object before serializing it into a JSON response.\nDuring the execution of the profile retrieval function, the backend service queries the database for the current user record. The application logic fails to exclude the sensitive password field—which contains a bcrypt-hashed representation of the user's password—from the serialized output. Consequently, the API inadvertently discloses this sensitive hash to the requesting client.\nThe attack flow proceeds as follows: 1) An attacker gains authenticated access to the system. 2) The attacker invokes the /api/v1/profile endpoint via an HTTP GET request. 3) The Nezha API, failing to perform input or output validation/filtering, returns a full JSON object containing the user's account details, including the 'password' field. 4) The attacker extracts the bcrypt hash from the response payload. 5) Once the hash is acquired, the attacker can export the data to an external environment to execute offline cracking attacks using tools such as Hashcat or John the Ripper. Because these attacks occur locally on the attacker's hardware, they bypass server-side rate limiting, account lockout policies, and security audit trails.\nThe vulnerable component is the API controller handling user profile requests. The impact is significant, as the exposure of bcrypt hashes provides a direct target for credential recovery. Since the endpoint does not enforce restrictive field selection, it remains possible to retrieve sensitive data that serves no functional purpose for a standard user profile fetch operation. This deficiency underscores a lack of secure coding practices in the API's Data Transfer Object (DTO) handling. Versions prior to 2.2.7 are confirmed as affected, and the vulnerability persists until the specific field is explicitly redacted from the API response cycle."
}