PT-2026-21766 · Nats · Nats Server
Pavel Kohout
·
Published
2026-01-01
·
Updated
2026-03-03
·
CVE-2026-27571
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NATS-Server versions prior to 2.11.2
NATS-Server versions prior to 2.12.3
Description
NATS-Server, a high-performance messaging system, has an issue in its WebSocket implementation. The server handles compressed messages via WebSocket negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation only bounded the size of a NATS message but did not independently bound the memory consumption during message construction. This allows an attacker to use a compression bomb, causing excessive memory consumption and potentially terminating the server process. The issue does not require valid NATS credentials to exploit, as compression negotiation occurs before authentication.
Recommendations
Update NATS-Server to version 2.11.2 or later.
Update NATS-Server to version 2.12.3 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nats Server