CVE-2026-101085
HIGH
7,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via the POST /api/v1/alert-rule endpoint to crash the dashboard process, which persists the rule and causes repeated crashes on restart, disabling all monitoring and control plane functionality.
197
Numeric Truncation Error
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Modify Memory
Applicable Platforms
Languages:
C, C++, Java, C#
https://github.com/nezhahq/nezha/security/advisories/GHSA-2qc6-x993-hjq9
https://github.com/nezhahq/nezha/security/advisories/GHSA-2qc6-x993-hjq9
https://www.vulncheck.com/advisories/nezha-before-2.3.8-denial-of-service-via-a…