CVE-2026-53523 | nezhahq nezha up to 2.1.x Header oauth2.go getRedirectURL Host redirect (GHSA-9rc6-8cjv-rcvx)
A vulnerability, which was classified as problematic, was found in nezhahq nezha up to 2.1.x. Affected by this issue is the function getRedirectURL of the file oauth2.go of the component Header Handler. Such manipulation of the argument Host leads to open redirect.
This vulnerability is listed as CVE-2026-53523. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More