Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58207

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the response window was safely bounded. This issue is fixed in versions 2.14.3 and 2.12.12.

A flaw was found in NATS Server. A client with the ability to send account-scoped connection monitoring requests could crash the server. This is achieved by providing pagination offset and limit values that cause an arithmetic overflow, leading to a Denial of Service (DoS).

Отчет

CVE.org and NVD independently assess this issue at different severities than Red Hat because CVE.org uses a Changed scope (S:C) in its CVSS vector, treating the crash as impacting components beyond the NATS Server process itself. Red Hat, consistent with NVDs own scoring, assesses the impact as scoped to the NATS Server process (Scope Unchanged), resulting in a CVSS score of 6.5 and a Moderate impact rating. Only account-scoped connection-monitoring requests can trigger the arithmetic overflow, and no Red Hat product runs an externally-reachable, unauthenticated NATS Server monitoring endpoint by default.

Меры по смягчению последствий

Upstream mitigation: restrict publish access to system request subjects (e.g. .REQ.ACCOUNT.*.CONNZ) for untrusted clients, and avoid no-auth NATS deployments where untrusted clients can publish to system monitoring request subjects. Upgrading to nats-server 2.14.3 or 2.12.12 (or later) fully resolves the issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Fix deferred
Red Hat Ceph Storage 5rhceph/snmp-notifier-rhel8Fix deferred
Red Hat Ceph Storage 6rhceph/snmp-notifier-rhel9Fix deferred
Red Hat Ceph Storage 7rhceph/snmp-notifier-rhel9Fix deferred
Red Hat Ceph Storage 8rhceph/snmp-notifier-rhel9Fix deferred
Red Hat Ceph Storage 9rhceph/snmp-notifier-rhel10Fix deferred
Red Hat Hardened Imagesnats-server2.12Not affected
Red Hat Hardened Imagesnats-server2.14Not affected
Red Hat OpenShift Container Platform 4openshift4/oc-mirror-plugin-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2498265github.com/nats-io/nats-server: NATS Server: Denial of Service via arithmetic overflow in connection monitoring pagination

EPSS

Процентиль: 43%
0.0056
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
28 дней назад

[Unknown description]

CVSS3: 7.7
nvd
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the response window was safely bounded. This issue is fixed in versions 2.14.3 and 2.12.12.

CVSS3: 7.7
msrc
23 дня назад

NATS Server: Remote crash via integer overflow in Connz pagination

CVSS3: 7.7
debian
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and ed ...

EPSS

Процентиль: 43%
0.0056
Низкий

6.5 Medium

CVSS3