Description
Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests.
Published: 2026-10-03
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

Nezha Dashboard versions 1.8.0 through 2.3.12 contain an improper locking flaw where a non‑deferred mutex unlock can leak on a nil‑map panic path. This leads to a deadlock of the notification subsystem when an authenticated non‑admin user issues four specific notification API calls, after which the system can be forced to exhaust memory with blocking requests. The flaw is classified as CWE‑667, and the attack results in a denial of service that prevents new notifications from being processed and may worsen with memory exhaustion.

Affected Systems

Affected systems include the Nezha Dashboard distributed by nezhahq. The vulnerability exists in any deployment of Nezha version 1.8.0 up to, but not including, 2.3.13. Each instance running the dashboard component is vulnerable until the upstream issue is fixed in 2.3.13 or later.

Risk and Exploitability

The CVSS score of 7.1 indicates a high likelihood of impact if exploited. The EPSS score is not available, so the current probability of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated API call from a non‑admin member within the organization, as the flaw requires privileged but non‑administrative access to trigger the deadlock path. Because the attack requires a relatively small number of API calls, an active attacker who can authenticate can easily force the deadlock, leading to a local or remote denial of service depending on the attacker's access scope. Mitigation involves applying the patched version or implementing controls to limit notification API usage.

Generated by OpenCVE AI on October 3, 2026 at 15:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Nezha 2.3.13 or newer, which includes the fix for the mutex deadlock.
  • Restrict access to the notification API so that only administrators or trusted users can invoke it, preventing non‑admin members from triggering the deadlock.
  • Monitor the health of the alerting subsystem and set resource limits to detect and contain memory exhaustion or excessive blocking requests.

Generated by OpenCVE AI on October 3, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Nezhahq
Nezhahq nezha
Vendors & Products Nezhahq
Nezhahq nezha

Sat, 03 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests.
Title Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock
Weaknesses CWE-667
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T12:14:39.317Z

Reserved: 2026-10-03T12:04:36.963Z

Link: CVE-2026-105113

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T14:16:37.823

Modified: 2026-10-03T14:16:37.823

Link: CVE-2026-105113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T16:00:14Z

Weaknesses