CVE-2026-33249
- EPSS 0.03%
- Veröffentlicht 25.03.2026 20:21:30
- Zuletzt bearbeitet 26.03.2026 16:20:55
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11.0 and prior to versions 2.11.15 and 2.12.6, a valid client which uses message tracing headers can indicate that the trace message...
CVE-2026-29785
- EPSS 0.09%
- Veröffentlicht 25.03.2026 19:38:44
- Zuletzt bearbeitet 26.03.2026 17:13:31
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the...
CVE-2026-27889
- EPSS 0.08%
- Veröffentlicht 25.03.2026 19:36:36
- Zuletzt bearbeitet 26.03.2026 17:13:16
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-...
CVE-2026-33215
- EPSS 0.02%
- Veröffentlicht 24.03.2026 21:16:28
- Zuletzt bearbeitet 26.03.2026 17:19:15
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasa...
CVE-2022-29946
- EPSS 0.11%
- Veröffentlicht 11.07.2024 21:15:10
- Zuletzt bearbeitet 15.04.2026 00:35:42
NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildca...