Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33218

Опубликовано: 25 мар. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
Версия до 2.11.15 (исключая)
cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
Версия от 2.12.0 (включая) до 2.12.6 (исключая)

EPSS

Процентиль: 45%
0.00616
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-1286

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.

CVSS3: 7.5
redhat
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.

CVSS3: 7.5
debian
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

CVSS3: 7.5
github
5 месяцев назад

NATS has pre-auth server panic via leafnode handling

EPSS

Процентиль: 45%
0.00616
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-1286