CVE-2026-105112: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in nezhahq nezha
Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to deadlock the alerting subsystem. Attackers can concurrently call the notification-group and batch-delete endpoints with oversized id lists to widen the race and close an ABBA cycle, permanently killing alert delivery until restart.
AI Analysis
Technical Summary
CVE-2026-105112 describes a concurrency vulnerability in Nezha (versions >=1.8.0 <2.3.13) where a lock-order inversion between UpdateGroup and DeleteGroup leads to a race condition. Authenticated users with low privileges can exploit this by making concurrent requests to notification-group and batch-delete endpoints with oversized ID lists, triggering an ABBA cycle deadlock. This deadlock halts the alerting subsystem, causing alert delivery to cease until a manual restart occurs.
Potential Impact
The vulnerability allows authenticated non-admin users to permanently disrupt the alerting subsystem by causing a deadlock. This results in loss of alert delivery until the affected system is restarted, potentially impacting monitoring and response capabilities.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, limit access to the affected endpoints to trusted users and consider operational procedures to detect and recover from alert subsystem deadlocks.
CVE-2026-105112: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in nezhahq nezha
Description
Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to deadlock the alerting subsystem. Attackers can concurrently call the notification-group and batch-delete endpoints with oversized id lists to widen the race and close an ABBA cycle, permanently killing alert delivery until restart.
CVSS v4.0
Score 6.0medium
Affected software
nezhahq
nezha
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-105112 describes a concurrency vulnerability in Nezha (versions >=1.8.0 <2.3.13) where a lock-order inversion between UpdateGroup and DeleteGroup leads to a race condition. Authenticated users with low privileges can exploit this by making concurrent requests to notification-group and batch-delete endpoints with oversized ID lists, triggering an ABBA cycle deadlock. This deadlock halts the alerting subsystem, causing alert delivery to cease until a manual restart occurs.
Potential Impact
The vulnerability allows authenticated non-admin users to permanently disrupt the alerting subsystem by causing a deadlock. This results in loss of alert delivery until the affected system is restarted, potentially impacting monitoring and response capabilities.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, limit access to the affected endpoints to trusted users and consider operational procedures to detect and recover from alert subsystem deadlocks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-10-03T12:04:36.963Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac10acea43b0b3b89c6cf62
Added to database: 10/03/2026, 14:01:50 UTC
Last enriched: 10/03/2026, 14:16:39 UTC
Last updated: 10/04/2026, 02:43:53 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.