CVE detail
CVE-2026-33218
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33218.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 25, 2026, 8:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2451450bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 25, 2026, 8:16 PM - https://access.redhat.com/security/cve/CVE-2026-33218access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 25, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:23345access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 25, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:22347access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 25, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:21769access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 25, 2026, 8:16 PM No excerpt available.
Exploitgithub.comMar 25, 2026, 8:16 PM- https://advisories.nats.io/CVE/secnote-2026-10.txtadvisories.nats.io
No excerpt available.
Vendor Advisoryadvisories.nats.ioMar 25, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-42579CVSS 7.5 · High
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints…
- CVE-2026-25513CVSS 8.3 · High
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection vulnerability in the…
- CVE-2023-44204CVSS 6.5 · Medium
An Improper Validation of Syntactic Correctness of Input vulnerability in Routing Protocol Daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, n…
- CVE-2023-32649CVSS 8.2 · High
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our…
- CVE-2023-27043CVSS 5.3 · Medium
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value o…
- CVE-2021-44695CVSS 4.9 · Medium
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.