Impact
Nezha Dashboard versions 1.8.0 through 2.3.12 contain an improper locking flaw where a non‑deferred mutex unlock can leak on a nil‑map panic path. This leads to a deadlock of the notification subsystem when an authenticated non‑admin user issues four specific notification API calls, after which the system can be forced to exhaust memory with blocking requests. The flaw is classified as CWE‑667, and the attack results in a denial of service that prevents new notifications from being processed and may worsen with memory exhaustion.
Affected Systems
Affected systems include the Nezha Dashboard distributed by nezhahq. The vulnerability exists in any deployment of Nezha version 1.8.0 up to, but not including, 2.3.13. Each instance running the dashboard component is vulnerable until the upstream issue is fixed in 2.3.13 or later.
Risk and Exploitability
The CVSS score of 7.1 indicates a high likelihood of impact if exploited. The EPSS score is not available, so the current probability of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated API call from a non‑admin member within the organization, as the flaw requires privileged but non‑administrative access to trigger the deadlock path. Because the attack requires a relatively small number of API calls, an active attacker who can authenticate can easily force the deadlock, leading to a local or remote denial of service depending on the attacker's access scope. Mitigation involves applying the patched version or implementing controls to limit notification API usage.
OpenCVE Enrichment