CVE-2026-105113: fallo de gravedad alta en nezhahq nezha
Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1epss 0.2%
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
noninguna fuente lo reporta
Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
nezhahq · nezhaCVEs relacionadas — nezhahq nezha
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-53519CRITICALNezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_keyEPSS 2.3%CVE-2026-62283CRITICALNezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership checkEPSS 0.6%CVE-2026-46716CRITICALNezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cronEPSS 0.5%CVE-2026-59155MEDIUMNezha Monitoring: DDNS and Notification credential exposure via unredacted list APIEPSS 0.5%CVE-2026-53522MEDIUMNezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoSEPSS 0.4%CVE-2026-53520MEDIUMNezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routingEPSS 0.4%