Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58250

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode INFO protocol messages before authentication and account setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.

A flaw was found in NATS Server, a high-performance messaging system. An unauthenticated attacker with network access to a leafnode listener, where compression is enabled, could exploit this vulnerability. By sending repeated leafnode INFO protocol messages during the pre-authentication handshake, the attacker can cause the server to crash. This leads to a Denial of Service (DoS), making the server unavailable to legitimate users.

Отчет

This is an Important denial of service vulnerability in NATS Server. An unauthenticated remote attacker with network access to a leafnode listener, configured with compression enabled, could repeatedly send INFO protocol messages during the pre-authentication handshake. This action would cause the NATS server to crash, leading to a denial of service for legitimate users.

Меры по смягчению последствий

To reduce exposure, disable compression on NATS Server leafnode listeners if not strictly required for your environment. Alternatively, implement network access controls to restrict connectivity to leafnode listeners to only trusted clients. This limits the ability of unauthenticated peers to initiate the vulnerable handshake.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesnats-server2.12Not affected
Red Hat Hardened Imagesnats-server2.14Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2498257github.com/nats-io/nats-server: NATS Server: Denial of Service via repeated leafnode INFO messages during pre-authentication

EPSS

Процентиль: 50%
0.00732
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
28 дней назад

[Unknown description]

CVSS3: 7.5
nvd
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode INFO protocol messages before authentication and account setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.

msrc
23 дня назад

NATS Server: Pre-auth server crash via double INFO in leafnode handshake

CVSS3: 7.5
debian
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and ed ...

EPSS

Процентиль: 50%
0.00732
Низкий

7.5 High

CVSS3