Description
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode INFO protocol messages before authentication and account setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.
Published: 2026-07-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NATS Server suffers a crash during the pre‑authentication leafnode handshake when an unauthenticated peer repeatedly sends leafnode INFO protocol messages before account setup, leading to a server crash and service disruption for all connections.

Affected Systems

The vulnerability affects NATS Server from the nats‑io vendor. All releases prior to version 2.12.8 and 2.11.17 are impacted. The issue is resolved in releases 2.12.8 and 2.11.17 and later.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity denial‑of-service flaw. The exploit requires unauthenticated network access to a leafnode listener with compression enabled, which is typically available to external peers. Based on the description, it is inferred that an external peer could reach the leafnode listener, making the attack vector possible from outside. EPSS indicates a very low but non‑zero probability of exploitation, with a score below 1%, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. Nonetheless, an attacker with network reach to the affected port could intentionally trigger the crash and disrupt availability.

Generated by OpenCVE AI on July 29, 2026 at 13:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade NATS Server to version 2.12.8 or later, or to version 2.11.17 or later. The update applies the fix that resolves the crash.
  • If you cannot upgrade immediately, temporarily disable compression for all leafnode connections, which prevents the double INFO trigger that leads to the crash.
  • Limit network exposure by restricting access to leafnode listeners so that only trusted or authenticated peers can initiate connections.

Generated by OpenCVE AI on July 29, 2026 at 13:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 10 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Nats
Nats nats Server
Vendors & Products Nats
Nats nats Server

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode INFO protocol messages before authentication and account setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.
Title NATS Server: Pre-auth server crash via double INFO in leafnode handshake
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Nats Nats Server
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-09T13:33:45.059Z

Reserved: 2026-06-29T21:54:30.330Z

Link: CVE-2026-58250

cve-icon Vulnrichment

Updated: 2026-07-09T13:33:39.593Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-08T19:48:55Z

Links: CVE-2026-58250 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T13:45:02Z

Weaknesses