CVE-2026-101085
Received Received - Intake

Nezha Alert Rule Validation Bypass Leads to DoS

Vulnerability report for CVE-2026-101085, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via the POST /api/v1/alert-rule endpoint to crash the dashboard process, which persists the rule and causes repeated crashes on restart, disabling all monitoring and control plane functionality.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nezha nezha to 2.3.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-197 Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Nezha before version 2.3.8 has a flaw where it does not properly validate alert rule types and duration limits. This allows authenticated non-admin users to create malicious rules that cause the alert evaluator to crash repeatedly. Attackers exploit this by sending a specially crafted rule via the POST /api/v1/alert-rule endpoint, which crashes the dashboard process and disables monitoring and control functions.

Detection Guidance

Check Nezha dashboard logs for repeated crashes or panic errors. Inspect POST requests to /api/v1/alert-rule for malformed alert rules. Verify if non-admin users can create alert rules.

Impact Analysis

This vulnerability can cause denial of service by crashing the Nezha dashboard, disabling all monitoring and control plane functions. It requires an attacker to have authenticated non-admin access but allows them to persistently disable the system by creating a malformed rule that survives restarts.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by disrupting monitoring and control plane functionality. The crash of the dashboard process due to malformed alert rules may prevent proper logging, alerting, and system oversight required for compliance audits and data protection measures.

Mitigation Strategies

Upgrade Nezha to version 2.3.8 or later. Restrict alert rule creation to administrators only. Monitor dashboard logs for crashes and remove any suspicious alert rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101085. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart