7.5

CVE-2026-58250

NATS Server: Pre-auth server crash via double INFO in leafnode handshake

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode INFO protocol messages before authentication and account setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxfoundationNats-server Version < 2.11.17
LinuxfoundationNats-server Version >= 2.12.0 < 2.12.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.402
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://github.com/nats-io/nats-server/commit/8dcb26eaea78fdcbe96dbee5986d6019fd5cb94a
Patch
https://github.com/nats-io/nats-server/commit/fc5fe39177533e9dbdd651d2458285bfae1dde27
Patch
https://github.com/nats-io/nats-server/releases/tag/v2.11.17
Release Notes
https://github.com/nats-io/nats-server/releases/tag/v2.12.8
Release Notes
https://github.com/nats-io/nats-server/security/advisories/GHSA-3g5q-cfh2-cq67
Vendor Advisory