CVE-2026-33219
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.00%
- Percentil entre todas las CVEs puntuadas: 62
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-770
- CWE-770
Referencias
- https://advisories.nats.io/CVE/secnote-2026-02.txt
- https://advisories.nats.io/CVE/secnote-2026-11.txt
- https://github.com/advisories/GHSA-qrvq-68c2-7grw
- https://github.com/nats-io/nats-server/security/advisories/GHSA-8r68-gvr4-jh7j
- https://access.redhat.com/errata/RHSA-2026:21769
- https://access.redhat.com/errata/RHSA-2026:22347
- https://access.redhat.com/errata/RHSA-2026:23345
- https://access.redhat.com/security/cve/CVE-2026-33219
- https://bugzilla.redhat.com/show_bug.cgi?id=2451445
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33219.json
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-33219",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-33219",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-25T20:10:18.603979Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "nats-io",
"product": "nats-server",
"versions": [
{
"status": "affected",
"version": "< 2.11.15"
},
{
"status": "affected",
"version": ">= 2.12.0-RC.1, < 2.12.6"
}
]
}
]
},
{
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"affectedData": [
{
"cpes": [
"cpe:/a:redhat:multicluster_globalhub:1.4::el9"
],
"vendor": "Red Hat",
"product": "Multicluster Global Hub 1.4.5",
"versions": [
{
"status": "unaffected",
"version": "1779579439",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:multicluster_globalhub:1.6::el9"
],
"vendor": "Red Hat",
"product": "Multicluster Global Hub 1.6.5",
"versions": [
{
"status": "unaffected",
"version": "1780167118",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:multicluster_globalhub:1.5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat multicluster global hub 1.5.3",
"versions": [
{
"status": "unaffected",
"version": "1778867753",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "multicluster-globalhub/multicluster-globalhub-grafana-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4",
"packageName": "openshift4/oc-mirror-plugin-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-03-25T20:16:32.777",
"references": [
{
"url": "https://advisories.nats.io/CVE/secnote-2026-02.txt",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://advisories.nats.io/CVE/secnote-2026-11.txt",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/advisories/GHSA-qrvq-68c2-7grw",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-8r68-gvr4-jh7j",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:21769",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:22347",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:23345",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-33219",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2451445",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33219.json",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment."
},
{
"lang": "es",
"value": "NATS-Server es un servidor de alto rendimiento para NATS.io, un sistema de mensajería nativo de la nube y del borde. Antes de las versiones 2.11.15 y 2.12.6, un cliente malicioso que puede conectarse al puerto de WebSockets puede causar un uso de memoria ilimitado en el nats-server antes de la autenticación; esto requiere el envío de una cantidad de datos correspondiente. Esta es una variante más leve de CVE-2026-27571. Ese problema anterior era una bomba de compresión, esta vulnerabilidad no lo es. Los ataques contra este nuevo problema, por lo tanto, requieren un ancho de banda significativo del cliente. Las versiones 2.11.15 y 2.12.6 contienen una corrección. Como solución alternativa, deshabilite los websockets si no son necesarios para la implementación del proyecto."
}
],
"lastModified": "2026-09-09T13:19:24.173",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13EA156E-2759-4586-A22E-CDEAAD4D610C",
"versionEndExcluding": "2.11.15"
},
{
"criteria": "cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E347CFB-C56D-4FD8-8DD8-3D34C08D7154",
"versionEndExcluding": "2.12.6",
"versionStartIncluding": "2.12.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}