Denial of Service Vulnerability in Nezha by NezhaHQ
CVE-2026-101085
7.1HIGH
What is CVE-2026-101085?
Nezha versions prior to 2.3.8 contain a vulnerability that allows authenticated non-administrator users to generate malformed alert rules, which fail to validate critical parameters such as type and duration. This can lead to server crashes by exploiting the alert evaluator goroutine. Attackers can leverage this flaw by sending specially crafted requests to the /api/v1/alert-rule endpoint, thereby persisting the invalid rule and causing recurrent crashes upon dashboard reboots. This vulnerability disables essential monitoring and control functionalities, posing significant risks to system integrity.
Affected Version(s)
nezha 0 < 2.3.8
nezha 2.3.8
