Impact
Ineffective guard around the sentinel worker leads to a nil dereference when a concurrent server delete attempts to access a stale reporter pointer. The resulting unrecovered panic crashes the entire Nezha instance, causing a denial of service for all monitored services and dashboards.
Affected Systems
Nezha versions 2.2.11 through 2.3.0 are affected. An authenticated user with a member role who owns an agent can issue a POST /api/v1/batch-delete/server request for their own server, triggering the race condition.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, so exploitation likelihood is uncertain, but any successful exploit immediately brings the entire instance offline, disrupting service availability.
OpenCVE Enrichment