Medium severity6.5NVD Advisory· Published Sep 27, 2026
CVE-2026-101085
CVE-2026-101085
Description
Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via the POST /api/v1/alert-rule endpoint to crash the dashboard process, which persists the rule and causes repeated crashes on restart, disabling all monitoring and control plane functionality.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.