CVE-2026-33219 Details
Description
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.
A denial-of-service vulnerability has been identified in NATS-Server versions prior to 2.11.15 and 2.12.6. This issue allows a malicious client to cause unbounded memory usage by sending a large amount of data over an unprotected WebSockets connection, before authentication is required. The vulnerability is a milder variant of CVE-2026-27571, as it does not involve a compression bomb, but still requires significant client bandwidth to exploit.
Users can upgrade to NATS-Server versions 2.11.15 or 2.12.6. If WebSockets are not needed for the deployment, they can be disabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:21769 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:22347 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:23345 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-33219 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2451445 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33219.json | redhat-SADP | |
| https://advisories.nats.io/CVE/secnote-2026-02.txt | [email protected] | MitigationVendor Advisory |
| https://advisories.nats.io/CVE/secnote-2026-11.txt | [email protected] | MitigationVendor Advisory |
| https://github.com/advisories/GHSA-qrvq-68c2-7grw | [email protected] | MitigationVendor Advisory |
| https://github.com/nats-io/nats-server/security/advisories/GHSA-8r68-gvr4-jh7j | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | redhat-SADP |
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation nats-server | < 2.11.15 >= 2.12.0, < 2.12.6 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | redhat-SADP |
| Aug 17, 2026 | CVE Modified | redhat-SADP |
| Aug 14, 2026 | CVE Modified | redhat-SADP |
| Aug 10, 2026 | CVE Modified | redhat-SADP |
| Aug 3, 2026 | CVE Modified | redhat-SADP |
| Jul 27, 2026 | CVE Modified | redhat-SADP |
| Jul 20, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Mar 25, 2026 | New CVE Received | [email protected] |