CVE-2026-27889 Details
Description
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server. This happens before authentication, and so is exposed to anyone who can connect to the websockets port. Versions 2.11.14 and 2.12.5 contains a fix. A workaround is available. The vulnerability only affects deployments which use WebSockets and which expose the network port to untrusted end-points. If one is able to do so, a defense in depth of restricting either of these will mitigate the attack.
A denial-of-service vulnerability has been identified in NATS-Server versions 2.2.0 prior to 2.11.14 and 2.12.5. The issue arises from a missing sanity check on WebSocket frames, allowing a remote attacker to cause a server crash by sending a crafted frame. This vulnerability is exposed to anyone who can connect to the WebSocket port, before authentication is required. The problem only affects deployments that use WebSockets and expose the WebSocket port to untrusted endpoints.
Users are advised to upgrade NATS-Server to version 2.11.14 or 2.12.5, both of which contain the necessary fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:21769 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:22347 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:23345 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-27889 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2451447 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27889.json | redhat-SADP | |
| https://advisories.nats.io/CVE/secnote-2026-03.txt | [email protected] | MitigationVendor Advisory |
| https://github.com/nats-io/nats-server/security/advisories/GHSA-pq2q-rcw4-3hr6 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1286 | Improper Validation of Syntactic Correctness of Input | redhat-SADP |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation nats-server | >= 2.2.0, < 2.11.14 >= 2.12.0, < 2.12.5 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | redhat-SADP |
| Aug 17, 2026 | CVE Modified | redhat-SADP |
| Aug 14, 2026 | CVE Modified | redhat-SADP |
| Aug 10, 2026 | CVE Modified | redhat-SADP |
| Aug 3, 2026 | CVE Modified | redhat-SADP |
| Jul 27, 2026 | CVE Modified | redhat-SADP |
| Jul 20, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Mar 25, 2026 | New CVE Received | [email protected] |