PT-2026-99716 · Nezha · Nezha
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nezha versions 2.2.11 through 2.3.0
Description
The service sentinel worker in
service/singleton/servicesentinel.go contains an incomplete fix for a nil dereference issue. An authenticated user with the member role who owns an agent can trigger a race condition by issuing a concurrent server delete request to the endpoint "/api/v1/batch-delete/server". This causes the worker to dereference a missing entry in the server list snapshot. Since the sentinel workers and the gRPC server lack a recovery interceptor, the resulting panic crashes the entire instance, leading to a denial of service.Recommendations
Update to version 2.3.1.
Exploit
Fix
DoS
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nezha