PT-2026-104573 · Nezha · Nezha
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Nezha versions 1.8.0 through 2.3.12
Description
A lock-order inversion exists within the
UpdateGroup and DeleteGroup functions. This flaw allows authenticated users without administrative privileges to cause a deadlock in the alerting subsystem. By concurrently calling the 'notification-group' and 'batch-delete' endpoints using oversized id lists, an attacker can create an ABBA cycle, which is a specific type of deadlock where two or more threads are blocked waiting for each other to release locks. This results in the permanent failure of alert delivery until the system is restarted.Recommendations
Update Nezha to version 2.3.13 or later.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nezha