NATS-Server
cpe:2.3:a:nats:nats_server:*:*:*:*:*:*:*
- >= 2.2.0, < 2.11.12
- >= 2.2.0, < 2.12.3
A denial-of-service vulnerability has been identified in NATS-Server versions prior to 2.11.15 and 2.12.6. This issue allows a malicious client to cause unbounded memory usage by sending a large amount of data over an unprotected WebSockets connection, before authentication is required. The vulnerability is a milder variant of CVE-2026-27571, as it does not involve a compression bomb, but still requires significant client bandwidth to exploit.
Exploitation of this vulnerability leads to excessive memory consumption, which can cause the operating system to terminate the NATS-Server process.
Users can upgrade to NATS-Server versions 2.11.15 or 2.12.6. If WebSockets are not needed for the deployment, they can be disabled.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.