PT-2026-76019 · Go · Github.Com/Naiba/Nezha+1

Publicado

2026-08-11

·

Atualizado

2026-08-11

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Nezha accepts service-monitor TaskResult messages from an authenticated agent based only on whether the reported service ID exists. The dashboard authenticates the agent and derives the reporter server ID from the gRPC stream, but the service-monitor result worker does not verify that the reporter server was selected for that service, belongs to the service owner, or was actually assigned that monitoring task.
A low-privilege user with a valid agent secret and one registered agent can submit forged monitoring results for another user's service ID. This allows cross-tenant corruption of service-monitor history and state, and can influence victim-owned service notifications.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

GO-2026-5119

Produtos afetados

Github.Com/Naiba/Nezha
Github.Com/Nezhahq/Nezha