CVE-2026-101085

Published: Set 27, 2026 Last Modified: Set 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 6,5
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via the POST /api/v1/alert-rule endpoint to crash the dashboard process, which persists the rule and causes repeated crashes on restart, disabling all monitoring and control plane functionality.

197

Numeric Truncation Error

Incomplete
Common Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Modify Memory
Applicable Platforms
Languages: C, C++, Java, C#
View CWE Details
https://github.com/nezhahq/nezha/security/advisories/GHSA-2qc6-x993-hjq9
https://github.com/nezhahq/nezha/security/advisories/GHSA-2qc6-x993-hjq9
https://www.vulncheck.com/advisories/nezha-before-2.3.8-denial-of-service-via-a…