—
GO-2026-5645
Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) in github.com/nezhahq/nezha
Details
Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) in github.com/nezhahq/nezha
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/nezhahq/nezha
Introduced in:
1.4.0 Fixed in: 1.14.15-0.20260517022419-d7526351cf97 Fix
go get github.com/nezhahq/nezha@v1.14.15-0.20260517022419-d7526351cf97