Github.Com Nats-Io Nats-Server vulnerabilities

3 known vulnerabilities affecting github.com/nats-io_nats-server.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-27571MEDIUM≥ 0, ≤ 1.4.12026-02-24
CVE-2026-27571 [MEDIUM] CWE-409 nats-server websockets are vulnerable to pre-auth memory DoS nats-server websockets are vulnerable to pre-auth memory DoS ### Impact The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. The implementation bound the memory size of a NATS message but did not independently bound the memory consumption of the memory stream when constructing a NATS message which might then fail validation for size reasons. A
ghsaosv
CVE-2022-28357CRITICAL≥ 2.2.0, < 2.7.42023-09-19
CVE-2022-28357 [CRITICAL] CWE-22 NATS nats-server allows directory traversal via unintended path to a management action NATS nats-server allows directory traversal via unintended path to a management action NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
ghsaosv
CVE-2020-28466HIGH≥ 0, < 2.2.02022-02-15
CVE-2020-28466 [HIGH] CWE-400 Denial of service in github.com/nats-io/nats-server/server Denial of service in github.com/nats-io/nats-server/server This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers - Running a NATS service which is exposed to untrusted users presents a heightened risk. Any remote execution flaw or equivalent serio
ghsaosv