Github.Com Nats-Io Nats-Server vulnerabilities
3 known vulnerabilities affecting github.com/nats-io_nats-server.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-27571MEDIUM≥ 0, ≤ 1.4.12026-02-24
CVE-2026-27571 [MEDIUM] CWE-409 nats-server websockets are vulnerable to pre-auth memory DoS
nats-server websockets are vulnerable to pre-auth memory DoS
### Impact
The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. The implementation bound the memory size of a NATS message but did not independently bound the memory consumption of the memory stream when constructing a NATS message which might then fail validation for size reasons.
A
ghsaosv
CVE-2022-28357CRITICAL≥ 2.2.0, < 2.7.42023-09-19
CVE-2022-28357 [CRITICAL] CWE-22 NATS nats-server allows directory traversal via unintended path to a management action
NATS nats-server allows directory traversal via unintended path to a management action
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
ghsaosv
CVE-2020-28466HIGH≥ 0, < 2.2.02022-02-15
CVE-2020-28466 [HIGH] CWE-400 Denial of service in github.com/nats-io/nats-server/server
Denial of service in github.com/nats-io/nats-server/server
This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers - Running a NATS service which is exposed to untrusted users presents a heightened risk. Any remote execution flaw or equivalent serio
ghsaosv