PT-2026-99716 · Nezha · Nezha

·

CVE-2026-101088

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v4.0

6.0

Medium

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nezha versions 2.2.11 through 2.3.0
Description The service sentinel worker in service/singleton/servicesentinel.go contains an incomplete fix for a nil dereference issue. An authenticated user with the member role who owns an agent can trigger a race condition by issuing a concurrent server delete request to the endpoint "/api/v1/batch-delete/server". This causes the worker to dereference a missing entry in the server list snapshot. Since the sentinel workers and the gRPC server lack a recovery interceptor, the resulting panic crashes the entire instance, leading to a denial of service.
Recommendations Update to version 2.3.1.

Exploit

Fix

DoS

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101088
GHSA-JX78-55P5-RWV5

Affected Products

Nezha