« Back to list

Linuxfoundation

Linuxfoundation Nats-server: vulnerabilities and CVEs

Linuxfoundation Nats-server has 36 published vulnerabilities, 26 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs36
Last 12 months26
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-58211Medium (5.4)0.29%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when…
CVE-2026-58208High (7.5)0.60%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT…
CVE-2026-58207Medium (6.5)0.56%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server…
CVE-2026-58254Medium (5.3)0.31%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were applied to ordinary client connections but not…
CVE-2026-58253High (8.8)0.37%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client…
CVE-2026-58252Medium (6.5)0.46%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could receive messages on denied subjects when a wildcard…
CVE-2026-58251Medium (6.5)0.46%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain…
CVE-2026-58250High (7.5)0.74%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled…
CVE-2026-58214Medium (4.3)0.35%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject…
CVE-2026-58213High (7.1)0.44%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were…
CVE-2026-58210High (7.5)0.74%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQTT client could cause the server to retain large incomplete MQTT…
CVE-2026-58209Medium (4.3)0.34%—Jul 8, 2026
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose…
CVE-2026-33249Medium (4.3)0.26%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11.0 and prior to versions 2.11.15 and 2.12.6, a valid client which uses message tracing headers can…
CVE-2026-33248Medium (4.2)0.17%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity…
CVE-2026-33223Medium (5.4)0.24%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of…
CVE-2026-33222Medium (4.9)0.34%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other…
CVE-2026-33247Medium (5.3)0.54%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv…
CVE-2026-33246Medium (5.4)0.24%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message header, providing information about a request. This is supposed to…
CVE-2026-33219Medium (5.3)1.0%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded…
CVE-2026-33218High (7.5)0.84%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a…
CVE-2026-33217Medium (6.5)0.37%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>`…
CVE-2026-33216High (7.5)0.63%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly…
CVE-2026-29785High (7.5)0.97%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then…
CVE-2026-27889High (7.5)0.84%—Mar 25, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could…
CVE-2026-33215Medium (6.5)0.28%—Mar 24, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by…
CVE-2026-27571High (7.5)0.73%—Feb 24, 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to…
CVE-2023-46129High (7.5)0.37%—Oct 31, 2023
NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support…
CVE-2023-47090Medium (6.5)0.66%—Oct 30, 2023
NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the…
CVE-2022-28357Critical (9.8)1.2%—Sep 19, 2023
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
CVE-2022-26652Medium (6.5)2.3%—Mar 10, 2022
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.

Other products by Linuxfoundation