PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-33218 nats-io CVE debrief

A High-Performance server for NATS.io, a cloud and edge native messaging system, is vulnerable to a denial-of-service (DoS) attack. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. This vulnerability can lead to service disruptions, emphasizing the need for prompt patching or mitigation. Defenders should assess their exposure and prioritize patching to prevent potential service disruptions.

Vendor
nats-io
Product
nats-server
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-25
Original CVE updated
2026-09-09
Advisory published
2026-03-25
Advisory updated
2026-09-09

Who should care

Defenders responsible for NATS-Server deployments should assess exposure and prioritize patching or mitigating this vulnerability to prevent potential service disruptions. This includes reviewing affected scope, verifying patch availability, and implementing compensating controls if necessary. Security teams should track exceptions and retest remediated assets to ensure the vulnerability is properly addressed.

Why it matters

Defenders should care about this vulnerability as it can lead to a denial-of-service (DoS) attack, potentially disrupting services. The vulnerability affects NATS-Server versions prior to 2.11.15 and 2.12.6, and defenders should prioritize patching or mitigating this vulnerability to prevent potential service disruptions.

  • Potential service disruption due to DoS attack
  • Need to verify and patch affected versions
  • Possible impact on system availability

Technical summary

The NATS-Server is vulnerable to a DoS attack due to a malformed message pre-authentication. A client which can connect to the leafnode port can crash the nats-server. This vulnerability affects NATS-Server versions prior to 2.11.15 and 2.12.6. Defenders should prioritize patching or mitigating this vulnerability to prevent potential service disruptions. The vulnerability has a CVSS score of 7.5, indicating a high severity level. The attack can be mitigated by patching or restricting access to the leafnode port. The vulnerability does not require authentication, making it easier to exploit.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability to prevent potential service disruptions.

Recommended defensive actions

  • Patch NATS-Server to version 2.11.15 or 2.12.6
  • Disable leafnode support if not needed
  • Restrict network connections to the leafnode port
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE record and NVD vulnerability detail page provide information on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability affects NATS-Server versions prior to 2.11.15 and 2.12.6. Defenders should verify the affected scope and review official advisories for guidance. Evidence is limited to publicly available sources, and further verification is recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-33218 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-33218

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-33218 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33218

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://advisories.nats.io/CVE/secnote-2026-10.txt

    [email protected] - Mitigation, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/nats-io/nats-server/security/advisories/GHSA-vprv-35vv-q339

    [email protected] - Mitigation, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:21769

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:22347

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:23345

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-33218

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33218.json

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.