Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58208

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.

A flaw was found in NATS Server. An unauthenticated client with access to the WebSocket listener could exploit a vulnerability where requests for the MQTT-over-WebSocket path were incorrectly routed into MQTT handling, even when MQTT was not configured. This allowed the client to access uninitialized MQTT state, leading to a server process crash. This can result in a Denial of Service (DoS) for the NATS Server.

Отчет

This Moderate flaw in NATS Server allows an unauthenticated remote attacker to cause a denial of service. The vulnerability arises from incorrect routing of WebSocket requests to uninitialized MQTT handling, even when MQTT is not configured, leading to a server crash. This impacts the availability of NATS Server deployments that expose a WebSocket listener, as it does not require specific MQTT configuration to exploit.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the NATS Server's WebSocket listener to trusted clients only using firewall rules. If the WebSocket listener is not required, it can be disabled in the NATS Server configuration. Disabling the WebSocket listener may impact services that rely on WebSocket connectivity to the NATS Server. After making configuration changes, ensure to restart the NATS Server process for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesnats-server2.12Not affected
Red Hat Hardened Imagesnats-server2.14Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2498254github.com/nats-io/nats-server: NATS Server: Denial of Service due to incorrect MQTT-over-WebSocket request routing

EPSS

Процентиль: 26%
0.00337
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.

CVSS3: 6.8
nvd
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.

CVSS3: 6.8
msrc
23 дня назад

NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled

CVSS3: 6.8
debian
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and ed ...

EPSS

Процентиль: 26%
0.00337
Низкий

6.8 Medium

CVSS3