CVE-2026-27889High· 7.5▾ MidnightPoC availableNATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
Last analysed / modified upstream
Exploit / PoC code exists
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server. This happens before authentication, and so is exposed to anyone who can connect to the websockets port. Versions 2.11.14 and 2.12.5 contains a fix. A workaround is available. The vulnerability only affects deployments which use WebSockets and which expose the network port to untrusted end-points. If one is able to do so, a defense in depth of restricting either of these will mitigate the attack.
nats-server >= 2.2.0, < 2.11.14nats-server >= 2.12.0, < 2.12.5Upgrade past the affected range:
nats-server 2.12.5Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-33218High· 7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
CVE-2026-33247High· 7.4NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
CVE-2026-33219Medium· 5.3NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
CVE-2026-33217High· 7.1NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
CVE-2026-33216High· 8.6NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
CVE-2026-29785High· 7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system