Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-58208

Опубликовано: 11 июл. 2026
Источник: msrc
CVSS3: 6.8
EPSS Низкий

Описание

NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled

EPSS

Процентиль: 44%
0.00593
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
28 дней назад

[Unknown description]

CVSS3: 6.8
redhat
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.

CVSS3: 6.8
nvd
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.

CVSS3: 6.8
debian
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and ed ...

EPSS

Процентиль: 44%
0.00593
Низкий

6.8 Medium

CVSS3