Denial of Service Vulnerability in Nezha Server Monitoring Tool
CVE-2026-101088

6MEDIUM

Key Information:

Vendor

Nezhahq

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101088?

The Nezha Server Monitoring Tool has a vulnerability in its service sentinel worker that can lead to a denial of service. In the affected versions ranging from 2.2.11 to 2.3.0, an authenticated user with the member role can exploit a race condition during a server deletion process. This occurs when the user initiates a concurrent delete request for their own server while the sentinel worker fails to properly validate the state of the server resource. This oversight allows for dereferencing a missing entry in a server list snapshot, resulting in an unrecoverable panic that crashes the entire instance. This issue was addressed in version 2.3.1 of the product.

Affected Version(s)

nezha 2.2.11 < 2.3.1

nezha 2.3.1

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
.