VDB
EN

GO-2026-5119

Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha

빠른 조치

GO-2026-5119 — github.com/nezhahq/nezha: 아래 명령으로 수정 버전으로 올리세요.

go get github.com/nezhahq/nezha@v1.14.15-0.20260521020202-02129f16fb15

상세

Nezha accepts service-monitor TaskResult messages from an authenticated agent based only on whether the reported service ID exists. The dashboard authenticates the agent and derives the reporter server ID from the gRPC stream, but the service-monitor result worker does not verify that the reporter server was selected for that service, belongs to the service owner, or was actually assigned that monitoring task.

A low-privilege user with a valid agent secret and one registered agent can submit forged monitoring results for another user's service ID. This allows cross-tenant corruption of service-monitor history and state, and can influence victim-owned service notifications.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Go / github.com/naiba/nezha
최초 영향 버전: 0.20.0

No fixed version published yet for github.com/naiba/nezha (go modules). Pin to a known-safe version or switch to an alternative.

Go / github.com/nezhahq/nezha
최초 영향 버전: 1.0.0 수정 버전: 1.14.15-0.20260521020202-02129f16fb15
수정 go get github.com/nezhahq/nezha@v1.14.15-0.20260521020202-02129f16fb15

참고