CVE-2026-101088: Time-of-check Time-of-use (TOCTOU) Race Condition in nezhahq nezha
Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously reported nil dereference denial of service (GHSA-qjpp-gffx-2wm9). The 2026-07-21 fix re-validated the service lifecycle under serviceResponseDataStoreLock but reused an already-captured, now stale reporter pointer and never re-validated the server, and that lock does not guard ServerShared. An authenticated user with the member role who owns an agent can issue a concurrent server delete (POST /api/v1/batch-delete/server) for their own server to win the race window, causing the worker to dereference a missing entry in the server list snapshot. Because the sentinel workers and the gRPC server have no recover()/recovery interceptor, the resulting panic is unrecovered and crashes the entire instance. This is fixed in version 2.3.1.
AI Analysis
Technical Summary
Nezha versions >=2.2.11 and <2.3.1 contain a TOCTOU race condition in the service sentinel worker component. The service lifecycle validation uses a lock (serviceResponseDataStoreLock) but reuses a stale reporter pointer and does not guard the ServerShared data structure, allowing a race window. An authenticated member user can issue a concurrent server deletion request to cause the sentinel worker to dereference a missing server entry, leading to an unrecovered panic that crashes the entire Nezha instance. This vulnerability is a result of an incomplete fix for a prior nil dereference denial of service issue (GHSA-qjpp-gffx-2wm9). The vulnerability is resolved in version 2.3.1.
Potential Impact
Exploitation requires authenticated access with member role and ownership of an agent. Successful exploitation causes a panic in the sentinel worker due to dereferencing a missing server entry, crashing the entire Nezha instance and resulting in denial of service. There is no indication of code execution or data compromise. The CVSS 4.0 score is 6.0 (medium severity) reflecting the impact of denial of service with high attack complexity and low privileges required.
Mitigation Recommendations
Upgrade Nezha to version 2.3.1 or later, where this race condition vulnerability is fixed. No other mitigations are indicated. Since the vulnerability requires authenticated access with member role, restricting user privileges may reduce risk but does not eliminate the vulnerability. Patch status is official-fix in 2.3.1.
CVE-2026-101088: Time-of-check Time-of-use (TOCTOU) Race Condition in nezhahq nezha
Description
Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously reported nil dereference denial of service (GHSA-qjpp-gffx-2wm9). The 2026-07-21 fix re-validated the service lifecycle under serviceResponseDataStoreLock but reused an already-captured, now stale reporter pointer and never re-validated the server, and that lock does not guard ServerShared. An authenticated user with the member role who owns an agent can issue a concurrent server delete (POST /api/v1/batch-delete/server) for their own server to win the race window, causing the worker to dereference a missing entry in the server list snapshot. Because the sentinel workers and the gRPC server have no recover()/recovery interceptor, the resulting panic is unrecovered and crashes the entire instance. This is fixed in version 2.3.1.
CVSS v4.0
Score 6.0medium
Affected software
nezhahq
nezha
pkg:golang/github.com/nezhahq/nezhaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Nezha versions >=2.2.11 and <2.3.1 contain a TOCTOU race condition in the service sentinel worker component. The service lifecycle validation uses a lock (serviceResponseDataStoreLock) but reuses a stale reporter pointer and does not guard the ServerShared data structure, allowing a race window. An authenticated member user can issue a concurrent server deletion request to cause the sentinel worker to dereference a missing server entry, leading to an unrecovered panic that crashes the entire Nezha instance. This vulnerability is a result of an incomplete fix for a prior nil dereference denial of service issue (GHSA-qjpp-gffx-2wm9). The vulnerability is resolved in version 2.3.1.
Potential Impact
Exploitation requires authenticated access with member role and ownership of an agent. Successful exploitation causes a panic in the sentinel worker due to dereferencing a missing server entry, crashing the entire Nezha instance and resulting in denial of service. There is no indication of code execution or data compromise. The CVSS 4.0 score is 6.0 (medium severity) reflecting the impact of denial of service with high attack complexity and low privileges required.
Mitigation Recommendations
Upgrade Nezha to version 2.3.1 or later, where this race condition vulnerability is fixed. No other mitigations are indicated. Since the vulnerability requires authenticated access with member role, restricting user privileges may reduce risk but does not eliminate the vulnerability. Patch status is official-fix in 2.3.1.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-27T20:29:07.432Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab98495f7a7c541067b9770
Added to database: 09/27/2026, 21:03:17 UTC
Last enriched: 09/27/2026, 21:18:15 UTC
Last updated: 09/28/2026, 02:25:47 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.