CVE-2026-101085: Nezha before 2.3.8 Denial of Service via Alert Rule

Published Sep 27, 2026
·
Updated

Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via the POST /api/v1/alert-rule endpoint to crash the dashboard process, which persists the rule and causes repeated crashes on restart, disabling all monitoring and control plane functionality.

Affected Software

1 affected component
Nezha<2.3.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Nezha to a version that resolves this vulnerability.

    Fixed in 2.3.8

Event History

Sep 27, 2026
CVE Published
via MITRE·08:49 PM
Data Sourced
via MITRE·08:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated non-administrator user who can submit requests to the POST /api/v1/alert-rule endpoint can create a crafted alert rule. No administrator privileges or user interaction are required.

2

What is the operational impact after exploitation?

The malformed rule can panic the alert evaluator goroutine and crash the dashboard process. Because the rule is persisted, the dashboard can crash repeatedly after restart, disabling monitoring and control-plane functionality.

3

Are installations before 2.3.8 affected by default?

The provided information identifies Nezha versions before 2.3.8 as affected, but does not state whether the vulnerable endpoint or alert-rule creation is enabled in a default deployment.

4

How can I determine whether an instance may already be affected?

Look for persisted malformed alert rules created through the alert-rule API and for dashboard crashes or repeated crashes after restart associated with alert evaluation. The provided information does not specify log messages or rule values that uniquely identify exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203