Vulnerability Details CVE-2026-33218
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 45.0%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-33218
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.1
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.2
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.3
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.4
-
cpe:2.3:a:linuxfoundation:nats-server:2.12.5