PT-2026-21766 · Nats · Nats Server

Pavel Kohout

·

Publicado

2026-01-01

·

Atualizado

2026-03-03

·

CVE-2026-27571

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NATS-Server versions prior to 2.11.2 NATS-Server versions prior to 2.12.3
Description NATS-Server, a high-performance messaging system, has an issue in its WebSocket implementation. The server handles compressed messages via WebSocket negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation only bounded the size of a NATS message but did not independently bound the memory consumption during message construction. This allows an attacker to use a compression bomb, causing excessive memory consumption and potentially terminating the server process. The issue does not require valid NATS credentials to exploit, as compression negotiation occurs before authentication.
Recommendations Update NATS-Server to version 2.11.2 or later. Update NATS-Server to version 2.12.3 or later.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-78372
AZL-78374
BIT-NATS-2026-27571
CVE-2026-27571
GHSA-QRVQ-68C2-7GRW
GO-2026-4533
SUSE-SU-2026:0757-1

Produtos afetados

Nats Server