pkg:Go/github.com/nats-io/nats-server

34 total CVEsCRITICAL2HIGH15MEDIUM16

✅ Check your installed version

All known vulnerabilities

  • CRITICAL9.8CVE-2022-28357NATS nats-server allows directory traversal via unintended path to a management action in github.com/nats-io/nats-server
    from 0
  • CRITICAL9.8CVE-2022-28357NATS nats-server allows directory traversal via unintended path to a management action in github.com/nats-io/nats-server
    >= 2.2.0, < 2.7.4
  • HIGH8.8CVE-2022-24450Incorrect Authorization in NATS nats-server in github.com/nats-io/nats-server
    from 0
  • HIGH8.6CVE-2026-33216NATS has MQTT plaintext password disclosure
    from 0
  • HIGH8.6CVE-2026-33216NATS has MQTT plaintext password disclosure
    from 0
  • HIGH7.5CVE-2026-27889NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
    from 0
  • HIGH7.5CVE-2026-27889NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
    from 0
  • HIGH7.5CVE-2026-33218NATS has pre-auth server panic via leafnode handling
    from 0
  • HIGH7.5CVE-2026-33218NATS has pre-auth server panic via leafnode handling
    from 0
  • HIGH7.5CVE-2026-29785NATS Server panic via malicious compression on leafnode port in github.com/nats-io/nats-server
    from 0
  • HIGH7.5CVE-2026-29785NATS Server panic via malicious compression on leafnode port in github.com/nats-io/nats-server
    from 0
  • HIGH7.5CVE-2020-28466Denial of service in github.com/nats-io/nats-server/server
    from 0
  • HIGH7.5CVE-2020-28466Denial of service in github.com/nats-io/nats-server/server
    from 0, < 2.2.0
  • HIGH7.5CVE-2019-13126Integer Overflow or Wraparound in NATS Server
    from 0
  • HIGH7.4CVE-2026-33247NATS credentials are exposed in monitoring port via command-line argv
    from 0
  • HIGH7.1CVE-2026-33217NATS allows MQTT clients to bypass ACL checks
    from 0
  • HIGH7.1CVE-2026-33217NATS allows MQTT clients to bypass ACL checks
    from 0
  • MEDIUM6.5CVE-2026-33215NATS is vulnerable to MQTT hijacking via Client ID
    from 0
  • MEDIUM6.5CVE-2022-29946NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjects in github.com/nats-io/nats-server
    from 0
  • MEDIUM6.5CVE-2022-26652Arbitrary file write in nats-server
    from 0
  • MEDIUM6.4CVE-2026-33246NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
    from 0
  • MEDIUM6.4CVE-2026-33246NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
    from 0
  • MEDIUM6.4CVE-2026-33223NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
    from 0
  • MEDIUM6.4CVE-2026-33223NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
    from 0
  • MEDIUM5.9CVE-2026-27571nats-server websockets are vulnerable to pre-auth memory DoS
    from 0, <= 1.4.1
  • MEDIUM5.9CVE-2026-27571nats-server websockets are vulnerable to pre-auth memory DoS
    from 0
  • MEDIUM5.3CVE-2026-33219NATS is vulnerable to pre-auth DoS through WebSockets client service
    from 0
  • MEDIUM5.3CVE-2026-33219NATS is vulnerable to pre-auth DoS through WebSockets client service
    from 0
  • MEDIUM4.9CVE-2026-33222NATS JetStream has an authorization bypass through its Management API
    from 0
  • MEDIUM4.9CVE-2026-33222NATS JetStream has an authorization bypass through its Management API
    from 0
  • MEDIUM4.3CVE-2026-33249NATS: Message tracing can be redirected to arbitrary subject
    from 0
  • MEDIUM4.2CVE-2026-33248NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
    from 0
  • MEDIUM4.2CVE-2026-33248NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
    from 0
  • CVE-2021-32026NATS server TLS missing ciphersuite settings when CLI flags used in github.com/nats-io/nats-server
    from 0