Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8r68-gvr4-jh7j

Опубликовано: 24 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

NATS is vulnerable to pre-auth DoS through WebSockets client service

Background

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.

The nats-server offers a WebSockets client service, used in deployments where browsers are the NATS clients.

Problem Description

A malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data.

This is a milder variant of NATS-advisory-ID 2026-02 (aka CVE-2026-27571; GHSA-qrvq-68c2-7grw). That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth.

Affected Versions

Any version before v2.12.6 or v2.11.15

Workarounds

Disable websockets if not required for project deployment.

Пакеты

Наименование

github.com/nats-io/nats-server/v2

go
Затронутые версииВерсия исправления

< 2.11.15

2.11.15

Наименование

github.com/nats-io/nats-server/v2

go
Затронутые версииВерсия исправления

>= 2.12.0-RC.1, < 2.12.6

2.12.6

Наименование

github.com/nats-io/nats-server

go
Затронутые версииВерсия исправления

Отсутствует

EPSS

Процентиль: 42%
0.00525
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.

CVSS3: 7.5
redhat
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.

CVSS3: 5.3
nvd
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.

CVSS3: 5.3
debian
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

EPSS

Процентиль: 42%
0.00525
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770