FlawAtlas
Search the atlas
CVE-2026-33218 High

NATS has pre-auth server panic via leafnode handling in github.com/nats-io/nats-server

NATS has pre-auth server panic via leafnode handling in github.com/nats-io/nats-server

Exploit probability 0.6%
Published March 26, 2026
Required by Not available
Last source change March 27, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

36 explicit affected versions

Bitnami nats
Go github.com/nats-io/nats-server
Go github.com/nats-io/nats-server/v2
Go github.com/nats-io/nats-server
Go github.com/nats-io/nats-server/v2

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities BIT-nats-2026-33218

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.

View original source
Open Source Vulnerabilities GHSA-vprv-35vv-q339

### Background NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The nats-server allows hub/spoke topologies using "leafnode" connections by other nats-servers. ### Problem Description A client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. ### Affected Versions Any version before v2.12.6 or v2.11.15 ### Workarounds 1. Disable leafnode support if not needed. 2. Restrict network connections to your leafnode port, if plausible without compromising the service offered. ### References * This document is canonically: <https://advisories.nats.io/CVE/secnote-2026-10.txt> * GHSA advisory: <https://github.com/nats-io/nats-server/security/advisories/GHSA-vprv-35vv-q339> * MITRE CVE entry: <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33218>

View original source
Open Source Vulnerabilities GO-2026-4837

NATS has pre-auth server panic via leafnode handling in github.com/nats-io/nats-server

View original source
Open Source Vulnerabilities CVE-2026-33218

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.

View original source

05 / REFERENCES

Further evidence