CVE-2026-33219

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*

History

30 Jun 2026, 03:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:21769 -
  • () https://access.redhat.com/errata/RHSA-2026:22347 -
  • () https://access.redhat.com/errata/RHSA-2026:23345 -
  • () https://access.redhat.com/security/cve/CVE-2026-33219 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2451445 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33219.json -

17 Jun 2026, 10:37

Type Values Removed Values Added
Summary
  • (es) NATS-Server es un servidor de alto rendimiento para NATS.io, un sistema de mensajería nativo de la nube y del borde. Antes de las versiones 2.11.15 y 2.12.6, un cliente malicioso que puede conectarse al puerto de WebSockets puede causar un uso de memoria ilimitado en el nats-server antes de la autenticación; esto requiere el envío de una cantidad de datos correspondiente. Esta es una variante más leve de CVE-2026-27571. Ese problema anterior era una bomba de compresión, esta vulnerabilidad no lo es. Los ataques contra este nuevo problema, por lo tanto, requieren un ancho de banda significativo del cliente. Las versiones 2.11.15 y 2.12.6 contienen una corrección. Como solución alternativa, deshabilite los websockets si no son necesarios para la implementación del proyecto.

26 Mar 2026, 17:15

Type Values Removed Values Added
CPE cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
References () https://advisories.nats.io/CVE/secnote-2026-02.txt - () https://advisories.nats.io/CVE/secnote-2026-02.txt - Mitigation, Vendor Advisory
References () https://advisories.nats.io/CVE/secnote-2026-11.txt - () https://advisories.nats.io/CVE/secnote-2026-11.txt - Mitigation, Vendor Advisory
References () https://github.com/advisories/GHSA-qrvq-68c2-7grw - () https://github.com/advisories/GHSA-qrvq-68c2-7grw - Mitigation, Vendor Advisory
References () https://github.com/nats-io/nats-server/security/advisories/GHSA-8r68-gvr4-jh7j - () https://github.com/nats-io/nats-server/security/advisories/GHSA-8r68-gvr4-jh7j - Mitigation, Vendor Advisory
First Time Linuxfoundation
Linuxfoundation nats-server

25 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 20:16

Updated : 2026-07-27 13:17


NVD link : CVE-2026-33219

Mitre link : CVE-2026-33219

CVE.ORG link : CVE-2026-33219


JSON object : View

Products Affected

linuxfoundation

  • nats-server
CWE
CWE-770

Allocation of Resources Without Limits or Throttling