Skip to main content

Vendor/product archive

linuxfoundation / nats-server CVEs

Beta · best-effort

36 CVEs tagged to linuxfoundation / nats-server2 Critical, 17 High, 17 Medium, 0 Low, 0 Unrated.

CVE-2026-27571

Published Feb 24, 2026

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSoc…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2023-47090

Published Oct 30, 2023

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated acces…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28357

Published Sep 19, 2023

NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28466

Published Mar 7, 2021

This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cy…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13126

Published Jul 29, 2019

An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker m…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-36 of 36 CVEsPage 2 of 2