CVE-2026-59155 Details
Description
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API credentials, including Cloudflare API tokens, TencentCloud SecretKeys, Slack, Discord, and Telegram webhook URLs with embedded bot tokens, and Authorization header values, without any field-level redaction. Any authenticated admin or PAT with nezha:ddns:read or nezha:notification:read scope can receive stored credentials through the listDDNS and listNotification handlers in a single API response. This issue is fixed in version 2.2.5.
A vulnerability in Nezha Monitoring prior to version 2.2.5 allows for the exposure of plaintext third-party API credentials through the GET /api/v1/ddns and GET /api/v1/notification endpoints. This issue affects all versions through 2.2.4. The vulnerable endpoints return full resource objects without redacting sensitive information, including Cloudflare API tokens, TencentCloud SecretKeys, and webhook URLs for Slack, Discord, and Telegram that contain embedded bot tokens. Any authenticated admin or PAT with the nezha:ddns:read or nezha:notification:read scope can access these stored credentials in a single API response.
Users can update to Nezha Monitoring version 2.2.5 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nezhahq/nezha/security/advisories/GHSA-ww5p-j6cj-6mqq | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/nezhahq/nezha/commit/39d398066d8c644fe452f74704e34ada6c7ab61e | [email protected] | Source CodeVendor |
| https://github.com/nezhahq/nezha/releases/tag/v2.2.5 | [email protected] | Release NotesVendor |
| https://github.com/nezhahq/nezha/security/advisories/GHSA-ww5p-j6cj-6mqq | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Nezha Monitoring | <= 2.2.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion