216.73.216.233

CVE-2026-29785

· Published 25/03/2026 20:16 · Modified 26/03/2026 17:13

Labels: CVE-2026-29785 2026-03-25CVE-2026-29785CWE-476[email protected]

Essential information

Published
25/03/2026 20:16
Modified
26/03/2026 17:13
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
linuxfoundation / nats-server cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
linuxfoundation / nats-server cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*

References