VendorsLinux Foundationnats-serverall versions
Vulnerabilities

Linux Foundation NATS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

36CVEs
CVE-2020-26892
The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
Published 2020-11-06 · Modified
9.8EPSS 0.021
CVE-2022-28357
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
Published 2023-09-19 · Modified
9.8EPSS 0.012
CVE-2022-24450
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.
Published 2022-02-08 · Modified
9.0EPSS 0.013
CVE-2026-58253
NATS Server: Route API Auth Bypass
Published 2026-07-08 · Analyzed
8.8EPSS 0.004
CVE-2026-33216
NATS has MQTT plaintext password disclosure
Published 2026-03-25 · Modified
8.6EPSS 0.004
CVE-2026-33217
NATS allows MQTT clients to bypass ACL checks
Published 2026-03-25 · Modified
8.1EPSS 0.003
CVE-2026-58207
NATS Server: Remote crash via integer overflow in Connz pagination
Published 2026-07-08 · Analyzed
7.7EPSS 0.006
CVE-2020-28466
Denial of Service (DoS)
Published 2021-03-07 · Modified
7.5EPSS 0.037
CVE-2020-26521
The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
Published 2020-11-06 · Modified
7.5EPSS 0.021
CVE-2019-13126
An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authenticated.
Published 2019-07-29 · Modified
7.5EPSS 0.018
CVE-2021-3127
NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.
Published 2021-03-16 · Modified
7.5EPSS 0.014
CVE-2026-58210
NATS Server: MQTT partial CONNECT packets can exhaust pre-auth memory
Published 2026-07-08 · Analyzed
7.5EPSS 0.007
CVE-2026-58250
NATS Server: Pre-auth server crash via double INFO in leafnode handshake
Published 2026-07-08 · Analyzed
7.5EPSS 0.007
CVE-2026-29785
NATS Server panic via malicious compression on leafnode port
Published 2026-03-25 · Modified
7.5EPSS 0.007
CVE-2026-33218
NATS has pre-auth server panic via leafnode handling
Published 2026-03-25 · Modified
7.5EPSS 0.006
CVE-2026-58208
NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
Published 2026-07-08 · Analyzed
7.5EPSS 0.006
CVE-2026-27889
NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
Published 2026-03-25 · Modified
7.5EPSS 0.006
CVE-2026-33219
NATS is vulnerable to pre-auth DoS through WebSockets client service
Published 2026-03-25 · Modified
7.5EPSS 0.005
CVE-2026-27571
nats-server websockets are vulnerable to pre-auth memory DoS
Published 2026-02-24 · Analyzed
7.5EPSS 0.005
CVE-2026-33247
NATS credentials are exposed in monitoring port via command-line argv
Published 2026-03-25 · Modified
7.5EPSS 0.004
CVE-2023-46129
xkeys Seal encryption used fixed key for all encryption
Published 2023-10-30 · Modified
7.5EPSS 0.004
CVE-2026-58213
NATS Server: MQTT SUBSCRIBE Protocol Injection via Leaf Node/Route Forwarding allows arbitrary NATS command injection
Published 2026-07-08 · Analyzed
7.1EPSS 0.004
CVE-2022-26652
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
Published 2022-03-10 · Modified
6.5EPSS 0.023
CVE-2023-47090
NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.
Published 2023-10-30 · Modified
6.5EPSS 0.007
CVE-2026-58252
NATS Server: Subscribe Authz Bypass via Wildcard-Overlap
Published 2026-07-08 · Analyzed
6.5EPSS 0.005
CVE-2026-58251
NATS Server: Queue Subscribe Authz Bypass
Published 2026-07-08 · Analyzed
6.5EPSS 0.005
CVE-2026-58254
NATS Server: Incomplete fix for CVE-2026-33249: Leaf node connections bypass Nats-Trace-Dest permission check
Published 2026-07-08 · Analyzed
6.5EPSS 0.003
CVE-2026-33215
NATS is vulnerable to MQTT hijacking via Client ID
Published 2026-03-24 · Analyzed
6.5EPSS 0.002
CVE-2026-33223
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
Published 2026-03-25 · Analyzed
6.4EPSS 0.002
CVE-2026-33246
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
Published 2026-03-25 · Analyzed
6.4EPSS 0.001
CVE-2026-58211
NATS Server: `no_auth_user` pre-CONNECT fast path bypasses user connection restrictions
Published 2026-07-08 · Analyzed
5.4EPSS 0.003
CVE-2026-33222
NATS JetStream has an authorization bypass through its Management API
Published 2026-03-25 · Analyzed
4.9EPSS 0.003
CVE-2026-58214
NATS Server: MQTT subscribe ACL bypass via $MQTT.deliver.pubrel prefix (incomplete fix for CVE-2026-33217)
Published 2026-07-08 · Analyzed
4.3EPSS 0.003
CVE-2026-58209
NATS Server: MQTT retained and QoS replay bypass subscribe deny filters
Published 2026-07-08 · Analyzed
4.3EPSS 0.003
CVE-2026-33249
NATS: Message tracing can be redirected to arbitrary subject
Published 2026-03-25 · Analyzed
4.3EPSS 0.002
CVE-2026-33248
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
Published 2026-03-25 · Analyzed
4.2EPSS 0.001