Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33219

Опубликовано: 25 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.

A flaw was found in NATS-Server. A malicious client connecting to the WebSockets port can cause unbounded memory use before authentication by sending a large amount of data. This resource exhaustion vulnerability can lead to a Denial of Service (DoS) for the server, making it unavailable to legitimate users.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/oc-mirror-plugin-rhel9Not affected
Multicluster Global Hub 1.4.5multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:2234701.06.2026
Red Hat multicluster global hub 1.5.0multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:2176928.05.2026
Red Hat multicluster global hub 1.6.0multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:2334504.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2451445github.com/nats-io/nats-server: NATS-Server: Denial of Service via unbounded memory use in WebSockets

EPSS

Процентиль: 42%
0.00525
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.

CVSS3: 5.3
nvd
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.

CVSS3: 5.3
debian
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

CVSS3: 5.3
github
5 месяцев назад

NATS is vulnerable to pre-auth DoS through WebSockets client service

EPSS

Процентиль: 42%
0.00525
Низкий

7.5 High

CVSS3