Impact
NATS Server incorrectly routes requests for the MQTT‑over‑WebSocket path into MQTT handling even when MQTT is not enabled. An unauthenticated client that can connect to the WebSocket listener can reach uninitialized MQTT state and cause the server process to crash. The flaw yields a denial of service to all clients consuming the messaging system.
Affected Systems
The vulnerability affects nats-io’s NATS Server versions prior to 2.14.3 and 2.12.12. Installations of 2.14.3, 2.12.12, or later include the fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 6.8 reflects a moderate severity. An EPSS score of <1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. The attack vector is a network connection to the WebSocket listener; no authentication is required, so any host with network reach to the server could trigger a crash, leading to a complete denial of service for the messaging platform.
OpenCVE Enrichment