Impact
Nezha 2.0.10 through 2.3.2 contains a URL validation flaw that allows an authenticated user to configure notification or DDNS webhooks that point to IPv6 addresses in the 2002::/16 6to4 or 64:ff9b:1::/48 transition ranges. Because those addresses satisfy the global unicast check, the validator accepts them, potentially enabling the dashboard to issue outbound HTTP requests to otherwise restricted IPv6 endpoints. No proven path exists to target private IPv4 networks, loopback, or metadata servers, limiting the impact to environments where the network routes these transition ranges to sensitive destinations.
Affected Systems
The vulnerability affects Nezhahq’s Nezha platform versions 2.0.10 through 2.3.2. Later releases, starting with 2.3.3, have fixed the issue by blocking both IPv6 transition prefixes.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, and the EPSS score is not available, indicating no known prevalent exploitation. It is not listed in the CISA KEV catalog. Exploitation requires an authenticated user who can configure webhook URLs and a network that forwards the 2002::/16 or 64:ff9b:1::/48 prefixes to a target. If those conditions are met, an attacker could force the dashboard to perform a request to a restricted IPv6 endpoint, potentially exposing internal services or bypassing security controls that rely on deny‑listing. The risk is moderate but non‑negligible for environments with unconventional IPv6 routing.
OpenCVE Enrichment