Improper Locking Vulnerability in Nezha Dashboard by Nezha
CVE-2026-105113
7.1HIGH
What is CVE-2026-105113?
The Nezha Dashboard, specifically versions prior to 2.3.13, suffers from an improper locking vulnerability. This flaw allows any authenticated non-admin user to exploit notification API calls, leading to a permanent deadlock of the alerting subsystem. Once this deadlock occurs, the system can be rendered inoperative, as it exhausts memory through blocking requests, resulting in a Denial of Service scenario.
Affected Version(s)
nezha 1.8.0 < 2.3.13
nezha 2.3.13
