CVE-2026-27571Improper Handling of Highly Compressed Data (Data Amplification) in Nats-server

Severity
7.5HIGHNVD
NVD5.3
EPSS
0.0%
top 91.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 24
Latest updateMar 25

Description

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation bound the memory size of a NATS message but did not independently bound the memory consumption of the memory stream when constructing a NATS message which might then fail validation for size reasons. An attacker can use a compression bo

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages8 packages

debiandebian/nats-server< nats-server 2.12.4-1 (forky)+1
CVEListV5nats-io/nats-server< 2.11.15+1
NVDlinuxfoundation/nats-server2.12.02.12.3+3
Gogithub.com/nats-io_nats-server_v22.12.0-RC.12.12.3+3
Debianlinuxfoundation/nats-server< 2.12.4-1+1

Patches

🔴Vulnerability Details

7
OSV
CVE-2026-33219: NATS-Server is a High-Performance server for NATS2026-03-25
GHSA
NATS is vulnerable to pre-auth DoS through WebSockets client service2026-03-24
OSV
NATS is vulnerable to pre-auth DoS through WebSockets client service2026-03-24
OSV
nats-server websockets are vulnerable to pre-auth memory DoS in github.com/nats-io/nats-server2026-02-25
OSV
CVE-2026-27571: NATS-Server is a High-Performance server for NATS2026-02-24

📋Vendor Advisories

5
Red Hat
github.com/nats-io/nats-server: NATS-Server: Denial of Service via unbounded memory use in WebSockets2026-03-25
Red Hat
nats-server: WebSockets pre-auth memory DoS2026-02-24
Microsoft
nats-server websockets are vulnerable to pre-auth memory DoS2026-02-10
Debian
CVE-2026-27571: nats-server - NATS-Server is a High-Performance server for NATS.io, a cloud and edge native me...2026
Debian
CVE-2026-33219: nats-server - NATS-Server is a High-Performance server for NATS.io, a cloud and edge native me...2026

🕵️Threat Intelligence

2
Wiz
CVE-2026-33219 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-27571 Impact, Exploitability, and Mitigation Steps | Wiz