CVE-2026-101088
Received Received - Intake

Nezha Monitoring Tool Race Condition DoS

Vulnerability report for CVE-2026-101088, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously reported nil dereference denial of service (GHSA-qjpp-gffx-2wm9). The 2026-07-21 fix re-validated the service lifecycle under serviceResponseDataStoreLock but reused an already-captured, now stale reporter pointer and never re-validated the server, and that lock does not guard ServerShared. An authenticated user with the member role who owns an agent can issue a concurrent server delete (POST /api/v1/batch-delete/server) for their own server to win the race window, causing the worker to dereference a missing entry in the server list snapshot. Because the sentinel workers and the gRPC server have no recover()/recovery interceptor, the resulting panic is unrecovered and crashes the entire instance. This is fixed in version 2.3.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nezha nezha From 2.2.11 (inc) to 2.3.1 (exc)
nezha nezha 2.3.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service vulnerability in Nezha, a server and website monitoring tool. It affects versions 2.2.11 to 2.3.0. An authenticated user with member role can exploit a race condition to crash the entire monitoring instance by deleting their own server during a specific operation. The crash occurs because the system dereferences a missing entry in the server list snapshot, causing a panic that is not recovered.

Detection Guidance

This vulnerability requires detecting Nezha versions between 2.2.11 and 2.3.0. Check installed versions with commands like 'nezha version' or inspect service logs for crashes in sentinel workers. Monitor for unrecovered panics in the service logs after server deletion requests.

Impact Analysis

If you use Nezha versions 2.2.11 to 2.3.0, an attacker with member role access could crash your monitoring system. This would disrupt server and website monitoring, potentially causing loss of visibility into system health and performance. The attack requires authentication but could lead to complete service outage for the monitoring tool.

Compliance Impact

This vulnerability causes a denial of service by crashing the Nezha monitoring instance through a nil dereference error. Such crashes could disrupt critical monitoring functions, potentially leading to undetected system failures or breaches. For GDPR, this may impact availability of data processing systems, while for HIPAA, it could affect the integrity and availability of health information systems.

Mitigation Strategies

Immediately upgrade Nezha to version 2.3.1 or later to address the nil dereference denial of service vulnerability. Ensure no authenticated users with member roles have unnecessary access to agent functionality.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101088. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart