CVE-2026-101085 HIGH

CVE-2026-101085: Nezha before 2.3.8 Denial of Service via Alert Rule

Vendor Nezhahq
Product nezha
Weakness CWE-197
Published September 27, 2026
Last update September 28, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via the POST /api/v1/alert-rule endpoint to crash the dashboard process, which persists the rule and causes repeated crashes on restart, disabling all monitoring and control plane functionality.

Key dates

02Disclosure timeline

September 27, 2026 CVE published
September 28, 2026 Record updated