Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101088— Nezha before 2.3.1 Denial of Service via Concurrent Server Delete

Quick assessment

Affected
nezhahq nezha
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

哪吒(Nezha)是一款服务器和网站监控工具。在版本 >= 2.2.11 且 < 2.3.1 中,服务哨兵工作者(service/singleton/servicesentinel.go)存在对先前报告的空指针解引用拒绝服务漏洞(GHSA-qjpp-gffx-2wm9)的不完全修复。2026-07-21 的修复虽然在 锁的保护下重新验证了服务生命周期,但重复使用了已被捕获、现已过期的 reporter 指针,且未对 Server 重新进行验证;此外,该锁并未保护 。拥有成员角色权限并拥有某个 Agent 的认证用户

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101088

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nezha before 2.3.1 Denial of Service via Concurrent Server Delete
Source: CVE Program / CVE List V5
Vulnerability Description
Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously reported nil dereference denial of service (GHSA-qjpp-gffx-2wm9). The 2026-07-21 fix re-validated the service lifecycle under serviceResponseDataStoreLock but reused an already-captured, now stale reporter pointer and never re-validated the server, and that lock does not guard ServerShared. An authenticated user with the member role who owns an agent can issue a concurrent server delete (POST /api/v1/batch-delete/server) for their own server to win the race window, causing the worker to dereference a missing entry in the server list snapshot. Because the sentinel workers and the gRPC server have no recover()/recovery interceptor, the resulting panic is unrecovered and crashes the entire instance. This is fixed in version 2.3.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nezhahq nezha 2.2.11 ~ 2.3.1 -

II. Public POCs for CVE-2026-101088

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101088

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101088 (1)

Other References for CVE-2026-101088 (1)

Same Patch Batch · nezhahq · 2026-09-27 · 6 CVEs total

CVE-2026-101090 9.8 CRITICAL Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri
CVE-2026-101085 6.5 MEDIUM Nezha before 2.3.8 Denial of Service via Alert Rule
CVE-2026-101086 6.5 MEDIUM Nezha Dashboard before 2.3.5 Task Type Validation Bypass
CVE-2026-101087 4.3 MEDIUM Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6
CVE-2026-101089 3.1 LOW Nezha before 2.2.7 Information Disclosure via /api/v1/profile

IV. Related Vulnerabilities

V. Comments for CVE-2026-101088

No comments yet


Leave a comment