VDB
KO

GO-2026-5439

Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members in github.com/nezhahq/nezha

Details

Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members in github.com/nezhahq/nezha

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/nezhahq/nezha
Introduced in: 1.4.0 Fixed in: 1.14.15-0.20260517034128-05e5da253519
Fix go get github.com/nezhahq/nezha@v1.14.15-0.20260517034128-05e5da253519

References