Логотип exploitDog
bind:CVE-2026-29785
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-29785

Количество 4

Количество 4

redhat логотип

CVE-2026-29785

6 дней назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-29785

6 дней назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-29785

6 дней назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-52jh-2xxh-pwh6

7 дней назад

NATS Server panic via malicious compression on leafnode port

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-29785

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.

CVSS3: 7.5
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-29785

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.

CVSS3: 7.5
0%
Низкий
6 дней назад
debian логотип
CVE-2026-29785

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

CVSS3: 7.5
0%
Низкий
6 дней назад
github логотип
GHSA-52jh-2xxh-pwh6

NATS Server panic via malicious compression on leafnode port

CVSS3: 7.5
0%
Низкий
7 дней назад

Уязвимостей на страницу