PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105113 nezhahq CVE debrief

CVE-2026-105113 is a high-severity vulnerability in Nezha Dashboard versions 1.8.0 before 2.3.13. An authenticated non-admin member can exploit an improper locking issue, causing a deadlock in the alerting subsystem and potentially leading to memory exhaustion through blocking requests. This can disrupt alerting and monitoring capabilities, impacting defenders' ability to respond to issues. The vulnerability highlights the need for careful management of authenticated user access and timely application of security updates.

Vendor
nezhahq
Product
nezha
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for Nezha Dashboard deployments, particularly those with authenticated user access, should assess potential exposure and impact. This includes reviewing current versions, managing user access, and considering upgrades or mitigations. Security teams and vulnerability management teams should prioritize verifying exposure and assessing potential impact to ensure timely mitigation.

Why it matters

CVE-2026-105113 is a high-severity vulnerability in Nezha Dashboard that can be exploited by authenticated non-admin members to cause a deadlock in the alerting subsystem, potentially leading to memory exhaustion. Defenders should prioritize verifying exposure, assessing potential impact, and considering upgrades or mitigations.

  • Potential denial-of-service (DoS) through alerting subsystem deadlock
  • Memory exhaustion through blocking requests
  • Increased risk for authenticated non-admin members
  • Need for verification of Nezha Dashboard version and exposure

Technical summary

The vulnerability is caused by an improper locking issue in Nezha Dashboard versions 1.8.0 before 2.3.13. An authenticated non-admin member can exploit this issue by issuing four notification API calls, causing a deadlock in the alerting subsystem. This can potentially lead to memory exhaustion through blocking requests, disrupting alerting and monitoring capabilities. The issue arises from a non-deferred mutex unlock on a nil-map panic path, highlighting the need for careful management of authenticated user access and timely application of security updates.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, focusing on authenticated users and alerting subsystems.

Recommended defensive actions

  • Verify Nezha Dashboard version and assess exposure
  • Restrict authenticated user access to alerting subsystems
  • Monitor for abnormal alerting subsystem behavior
  • Consider upgrading to Nezha Dashboard version 2.3.13 or later
  • Review compensating controls for exposed systems
  • Track exceptions and retest remediated assets
  • Check relevant monitoring, detection, and logs for exposed assets

Evidence notes

The CVE description and source references provide details on the improper locking vulnerability and its potential impact on the alerting subsystem. The vulnerability is caused by a non-deferred mutex unlock on a nil-map panic path. Source references confirm the vulnerability's existence and provide additional context on its exploitation. Defenders should verify Nezha Dashboard versions, assess exposure, and consider upgrades or mitigations. Evidence is limited to CVE and NVD details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105113 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105113

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105113 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105113

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.