CVE-2026-101089 - Nezha before 2.2.7 Information Disclosure via /api/v1/profile
CVE ID :CVE-2026-101089
Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 55 minutes ago
Description :Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rate limiting or audit trail constraints.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 55 minutes ago
Description :Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rate limiting or audit trail constraints.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...