VYPR

Vendor CVEs

Nats Io

All CVEs

34 total · sorted by risk
  • CVE-2022-24450HigFeb 8, 2022
    risk 0.57cvss 8.8epss 0.01

    NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.

  • CVE-2025-30215CriApr 16, 2025
    risk 0.55cvss 9.6epss 0.01

    NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.27 and 2.11.1, the management of JetStream assets happens with messages in the $JS. subject namespace in the system account; this…

  • CVE-2026-58253HigJul 8, 2026
    risk 0.50cvss 8.8epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could also apply to route or leafnode listeners,…

  • CVE-2026-33216HigMar 25, 2026
    risk 0.49cvss 8.6epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and…

  • CVE-2026-58207HigJul 8, 2026
    risk 0.43cvss 7.7epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that…

  • CVE-2026-58250HigJul 8, 2026
    risk 0.42cvss 7.5epss 0.01

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication…

  • CVE-2026-58210HigJul 8, 2026
    risk 0.42cvss 7.5epss 0.01

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQTT client could cause the server to retain large incomplete MQTT CONNECT packets before authentication completed, consuming server…

  • CVE-2026-33218HigMar 25, 2026
    risk 0.42cvss 7.5epss 0.01

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15…

  • CVE-2026-29785HigMar 25, 2026
    risk 0.42cvss 7.5epss 0.01

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a…

  • CVE-2026-27889HigMar 25, 2026
    risk 0.42cvss 7.5epss 0.01

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server. This happens before…

  • CVE-2023-46129HigOct 31, 2023
    risk 0.42cvss 7.5epss 0.00

    NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is…

  • CVE-2021-3127HigMar 16, 2021
    risk 0.42cvss 7.5epss 0.01

    NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.

  • CVE-2026-33247HigMar 25, 2026
    risk 0.41cvss 7.4epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any…

  • CVE-2022-29946MedJul 11, 2024
    risk 0.41cvss 6.3epss 0.00

    NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit…

  • CVE-2026-58213HigJul 8, 2026
    risk 0.39cvss 7.1epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode…

  • CVE-2026-33217HigMar 25, 2026
    risk 0.39cvss 7.1epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT…

  • CVE-2026-58208MedJul 8, 2026
    risk 0.37cvss 6.8epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an…

  • CVE-2026-58254MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were applied to ordinary client connections but not consistently to messages arriving through leafnode connections,…

  • CVE-2026-58252MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could receive messages on denied subjects when a wildcard subscription overlapped with a configured wildcard deny rule…

  • CVE-2026-58251MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by using a queue subscription, because…

  • CVE-2026-33223MedMar 25, 2026
    risk 0.35cvss 6.4epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from…

  • CVE-2026-33246MedMar 25, 2026
    risk 0.35cvss 6.4epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message header, providing information about a request. This is supposed to provide enough information to allow for account/user…

  • CVE-2026-33215MedMar 24, 2026
    risk 0.35cvss 6.5epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and…

  • CVE-2022-26652MedMar 10, 2022
    risk 0.35cvss 6.5epss 0.02

    NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.

  • CVE-2026-27571MedFeb 24, 2026
    risk 0.31cvss 5.9epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation bound the…

  • CVE-2026-58211MedJul 8, 2026
    risk 0.28cvss 5.4epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when the first client operation was not CONNECT, bypassing…

  • CVE-2026-33219MedMar 25, 2026
    risk 0.27cvss 5.3epss 0.01

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this…

  • CVE-2026-33222MedMar 25, 2026
    risk 0.25cvss 4.9epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected…

  • CVE-2026-58214MedJul 8, 2026
    risk 0.21cvss 4.3epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing configured subscribe permissions and…

  • CVE-2026-58209MedJul 8, 2026
    risk 0.21cvss 4.3epss 0.00

    NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule…

  • CVE-2026-33249MedMar 25, 2026
    risk 0.21cvss 4.3epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11.0 and prior to versions 2.11.15 and 2.12.6, a valid client which uses message tracing headers can indicate that the trace messages can be sent to an arbitrary…

  • CVE-2026-33248MedMar 25, 2026
    risk 0.20cvss 4.2epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns…

  • CVE-2021-32026lowMay 14, 2024
    risk 0.00cvss epss 0.00

    (This advisory is canonically <https://advisories.nats.io/CVE/CVE-2021-32026.txt>) ### Problem Description The NATS server by default uses a restricted set of modern ciphersuites for TLS. This selection can be overridden through configuration. The defaults include just RSA…

  • CVE-2020-28466HigMar 7, 2021
    risk 0.00cvss 7.5epss 0.04

    This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users…