CVE-2026-105112 MEDIUM

CVE-2026-105112: Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints

Vendor Nezhahq
Product nezha
Weakness CWE-362
Published October 3, 2026
Last update October 3, 2026

CVSS base score

6.0/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to deadlock the alerting subsystem. Attackers can concurrently call the notification-group and batch-delete endpoints with oversized id lists to widen the race and close an ABBA cycle, permanently killing alert delivery until restart.

Key dates

02Disclosure timeline

October 3, 2026 CVE published

Related vulnerabilities

04Related CVE