Linuxfoundation
Linuxfoundation Nats-server: vulnerabilities and CVEs
Linuxfoundation Nats-server has 36 published vulnerabilities, 26 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs36
Last 12 months26
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58211 | Medium (5.4) | 0.29% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when… |
| CVE-2026-58208 | High (7.5) | 0.60% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT… |
| CVE-2026-58207 | Medium (6.5) | 0.56% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server… |
| CVE-2026-58254 | Medium (5.3) | 0.31% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were applied to ordinary client connections but not… |
| CVE-2026-58253 | High (8.8) | 0.37% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client… |
| CVE-2026-58252 | Medium (6.5) | 0.46% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could receive messages on denied subjects when a wildcard… |
| CVE-2026-58251 | Medium (6.5) | 0.46% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain… |
| CVE-2026-58250 | High (7.5) | 0.74% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled… |
| CVE-2026-58214 | Medium (4.3) | 0.35% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject… |
| CVE-2026-58213 | High (7.1) | 0.44% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were… |
| CVE-2026-58210 | High (7.5) | 0.74% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQTT client could cause the server to retain large incomplete MQTT… |
| CVE-2026-58209 | Medium (4.3) | 0.34% | — | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose… |
| CVE-2026-33249 | Medium (4.3) | 0.26% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11.0 and prior to versions 2.11.15 and 2.12.6, a valid client which uses message tracing headers can… |
| CVE-2026-33248 | Medium (4.2) | 0.17% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity… |
| CVE-2026-33223 | Medium (5.4) | 0.24% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of… |
| CVE-2026-33222 | Medium (4.9) | 0.34% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other… |
| CVE-2026-33247 | Medium (5.3) | 0.54% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv… |
| CVE-2026-33246 | Medium (5.4) | 0.24% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message header, providing information about a request. This is supposed to… |
| CVE-2026-33219 | Medium (5.3) | 1.0% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded… |
| CVE-2026-33218 | High (7.5) | 0.84% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a… |
| CVE-2026-33217 | Medium (6.5) | 0.37% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>`… |
| CVE-2026-33216 | High (7.5) | 0.63% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly… |
| CVE-2026-29785 | High (7.5) | 0.97% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then… |
| CVE-2026-27889 | High (7.5) | 0.84% | — | Mar 25, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could… |
| CVE-2026-33215 | Medium (6.5) | 0.28% | — | Mar 24, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by… |
| CVE-2026-27571 | High (7.5) | 0.73% | — | Feb 24, 2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to… |
| CVE-2023-46129 | High (7.5) | 0.37% | — | Oct 31, 2023 | NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support… |
| CVE-2023-47090 | Medium (6.5) | 0.66% | — | Oct 30, 2023 | NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the… |
| CVE-2022-28357 | Critical (9.8) | 1.2% | — | Sep 19, 2023 | NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account. |
| CVE-2022-26652 | Medium (6.5) | 2.3% | — | Mar 10, 2022 | NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected. |