PT-2026-104573 · Nezha · Nezha

·

CVE-2026-105112

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Nezha versions 1.8.0 through 2.3.12
Description A lock-order inversion exists within the UpdateGroup and DeleteGroup functions. This flaw allows authenticated users without administrative privileges to cause a deadlock in the alerting subsystem. By concurrently calling the 'notification-group' and 'batch-delete' endpoints using oversized id lists, an attacker can create an ABBA cycle, which is a specific type of deadlock where two or more threads are blocked waiting for each other to release locks. This results in the permanent failure of alert delivery until the system is restarted.
Recommendations Update Nezha to version 2.3.13 or later.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105112

Affected Products

Nezha