Post
OffSequence
offseq.bsky.social
did:plc:t5t6qep2vfipbi7f54demwev
Nezha 2.2.3 faces CRITICAL risk: OAuth2 open redirect (CVE-2026-101090) lets attackers hijack logins if dashboard_host is empty. Set to trusted value — no patch yet. https://radar.offseq.com/threat/cve-2026-101090-url-redirection-to-untrusted-site-open-redirect-in-nezhahq-nezha-17f76beacc249b5e #...
2026-09-28T01:30:26.864Z