CVE-2026-58207 Details
Description
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the response window was safely bounded. This issue is fixed in versions 2.14.3 and 2.12.12.
A denial-of-service vulnerability has been identified in NATS Server versions prior to 2.14.3 and 2.12.12. The issue arises in account-scoped connection monitoring requests, where a client can send pagination Offset and Limit values that cause an integer overflow. This overflow disrupts internal arithmetic, leading to a server crash. The vulnerability is particularly concerning in no-auth deployments, where any client with network access can exploit it. In multi-tenant deployments, the impact depends on the tenant's ability to publish to the imported account monitoring request subject.
Users can upgrade to NATS Server versions 2.14.3 or 2.12.12, both of which include the necessary fix. Instructions for downloading these versions are available on the NATS Server GitHub Releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation nats-server | >= 2.12.0, < 2.12.12 >= 2.14.0, < 2.14.3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |