CVE-2026-33218

EUVD-2026-15968
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 46.19%
Affected Products (NVD)
VendorProductVersion
linuxfoundationnats-server
𝑥
< 2.11.15
linuxfoundationnats-server
2.12.0 ≤
𝑥
< 2.12.6
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatMulticluster Global Hub 1.4.5
1779579439 ≤
𝑥
< *
ADP
Red HatRed Hat multicluster global hub 1.5.0
1778867753 ≤
𝑥
< *
ADP
Red HatRed Hat multicluster global hub 1.6.0
1780167118 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
nats-server
bookworm
vulnerable
forky
2.14.3-1
fixed
sid
2.14.3-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nats-server
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage