PT-2026-21766 · Nats · Nats Server

Pavel Kohout

·

Published

2026-01-01

·

Updated

2026-03-03

·

CVE-2026-27571

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NATS-Server versions prior to 2.11.2 NATS-Server versions prior to 2.12.3
Description NATS-Server, a high-performance messaging system, has an issue in its WebSocket implementation. The server handles compressed messages via WebSocket negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation only bounded the size of a NATS message but did not independently bound the memory consumption during message construction. This allows an attacker to use a compression bomb, causing excessive memory consumption and potentially terminating the server process. The issue does not require valid NATS credentials to exploit, as compression negotiation occurs before authentication.
Recommendations Update NATS-Server to version 2.11.2 or later. Update NATS-Server to version 2.12.3 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

AZL-78372
AZL-78374
BIT-NATS-2026-27571
CVE-2026-27571
GHSA-QRVQ-68C2-7GRW
GO-2026-4533
SUSE-SU-2026:0757-1

Affected Products

Nats Server