Vulnerability Description
Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/nezhahq/nezha/security/advisories/GHSA-7j7v-j77m-6g3m
- https://www.vulncheck.com/advisories/nezha-1.8.0-before-2.3.13-denial-of-service
FAQ
What is CVE-2026-105113?
CVE-2026-105113 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four n...
How severe is CVE-2026-105113?
CVE-2026-105113 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-105113?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.