Improper Locking Vulnerability in Nezha Dashboard by Nezha
CVE-2026-105113

7.1HIGH

Key Information:

Vendor

Nezhahq

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105113?

The Nezha Dashboard, specifically versions prior to 2.3.13, suffers from an improper locking vulnerability. This flaw allows any authenticated non-admin user to exploit notification API calls, leading to a permanent deadlock of the alerting subsystem. Once this deadlock occurs, the system can be rendered inoperative, as it exhausts memory through blocking requests, resulting in a Denial of Service scenario.

Affected Version(s)

nezha 1.8.0 < 2.3.13

nezha 2.3.13

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
.