PatchSiren cyber security CVE debrief
CVE-2026-33218 nats-io CVE debrief
A High-Performance server for NATS.io, a cloud and edge native messaging system, is vulnerable to a denial-of-service (DoS) attack. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. This vulnerability can lead to service disruptions, emphasizing the need for prompt patching or mitigation. Defenders should assess their exposure and prioritize patching to prevent potential service disruptions.
- Vendor
- nats-io
- Product
- nats-server
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-25
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-03-25
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for NATS-Server deployments should assess exposure and prioritize patching or mitigating this vulnerability to prevent potential service disruptions. This includes reviewing affected scope, verifying patch availability, and implementing compensating controls if necessary. Security teams should track exceptions and retest remediated assets to ensure the vulnerability is properly addressed.
Why it matters
Defenders should care about this vulnerability as it can lead to a denial-of-service (DoS) attack, potentially disrupting services. The vulnerability affects NATS-Server versions prior to 2.11.15 and 2.12.6, and defenders should prioritize patching or mitigating this vulnerability to prevent potential service disruptions.
- Potential service disruption due to DoS attack
- Need to verify and patch affected versions
- Possible impact on system availability
Technical summary
The NATS-Server is vulnerable to a DoS attack due to a malformed message pre-authentication. A client which can connect to the leafnode port can crash the nats-server. This vulnerability affects NATS-Server versions prior to 2.11.15 and 2.12.6. Defenders should prioritize patching or mitigating this vulnerability to prevent potential service disruptions. The vulnerability has a CVSS score of 7.5, indicating a high severity level. The attack can be mitigated by patching or restricting access to the leafnode port. The vulnerability does not require authentication, making it easier to exploit.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability to prevent potential service disruptions.
Recommended defensive actions
- Patch NATS-Server to version 2.11.15 or 2.12.6
- Disable leafnode support if not needed
- Restrict network connections to the leafnode port
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability affects NATS-Server versions prior to 2.11.15 and 2.12.6. Defenders should verify the affected scope and review official advisories for guidance. Evidence is limited to publicly available sources, and further verification is recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-33218 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-33218
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-33218 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33218
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://advisories.nats.io/CVE/secnote-2026-10.txt
[email protected] - Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/nats-io/nats-server/security/advisories/GHSA-vprv-35vv-q339
[email protected] - Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:21769
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:22347
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:23345
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-33218
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33218.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.