CVE-2026-105112: falha de média gravidade em nezhahq nezha
Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6epss 0.2%
probabilidade de exploração
0.2%top 93% das CVEs
exploração observada
nãonenhuma fonte reporta
Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to deadlock the alerting subsystem. Attackers can concurrently call the notification-group and batch-delete endpoints with oversized id lists to widen the race and close an ABBA cycle, permanently killing alert delivery until restart.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Produtos afetados
nezhahq · nezhaCVEs relacionadas — nezhahq nezha
No mesmo produto, das mais perigosas para as menos.
CVE-2026-53519CRITICALNezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_keyEPSS 2.3%CVE-2026-62283CRITICALNezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership checkEPSS 0.6%CVE-2026-46716CRITICALNezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cronEPSS 0.5%CVE-2026-59155MEDIUMNezha Monitoring: DDNS and Notification credential exposure via unredacted list APIEPSS 0.5%CVE-2026-53522MEDIUMNezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoSEPSS 0.4%CVE-2026-53520MEDIUMNezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routingEPSS 0.4%