CVE-2026-105113: Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock
Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated non-admin member can exploit it. The attack is network-reachable and does not require user interaction.
Are default deployments affected?
The provided information does not identify any configuration prerequisite beyond running an affected Nezha Dashboard version and allowing an authenticated non-admin member to access the notification API.
What does an attacker need to do?
The attacker needs to issue four notification API calls. This permanently deadlocks the alerting subsystem and can then be followed by blocking requests that exhaust memory.
How can I tell whether my deployment is vulnerable?
Deployments running Nezha Dashboard version 1.8.0 through versions before 2.3.13 are affected. A permanently unresponsive alerting subsystem after notification API activity, combined with growing memory use from blocking requests, is consistent with exploitation.