CVE-2026-101085: Nezha before 2.3.8 Denial of Service via Alert Rule
Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via the POST /api/v1/alert-rule endpoint to crash the dashboard process, which persists the rule and causes repeated crashes on restart, disabling all monitoring and control plane functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nezhato a version that resolves this vulnerability.Fixed in 2.3.8
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated non-administrator user who can submit requests to the POST /api/v1/alert-rule endpoint can create a crafted alert rule. No administrator privileges or user interaction are required.
What is the operational impact after exploitation?
The malformed rule can panic the alert evaluator goroutine and crash the dashboard process. Because the rule is persisted, the dashboard can crash repeatedly after restart, disabling monitoring and control-plane functionality.
Are installations before 2.3.8 affected by default?
The provided information identifies Nezha versions before 2.3.8 as affected, but does not state whether the vulnerable endpoint or alert-rule creation is enabled in a default deployment.
How can I determine whether an instance may already be affected?
Look for persisted malformed alert rules created through the alert-rule API and for dashboard crashes or repeated crashes after restart associated with alert evaluation. The provided information does not specify log messages or rule values that uniquely identify exploitation.