PT-2026-104574 · Unknown · Nezha Dashboard
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nezha Dashboard versions 1.8.0 through 2.3.12
Description
An improper locking issue exists where a non-deferred mutex unlock leaks during a nil-map panic path. An authenticated non-admin member can exploit this by issuing four notification API calls to permanently deadlock the alerting subsystem, subsequently exhausting memory through blocking requests.
Recommendations
Update Nezha Dashboard to version 2.3.13 or later.
Exploit
Fix
DoS
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nezha Dashboard