Bug 2451447 (CVE-2026-27889) - CVE-2026-27889 github.com/nats-io/nats-server: NATS-Server: Denial of Service via malformed WebSockets frame
Summary: CVE-2026-27889 github.com/nats-io/nats-server: NATS-Server: Denial of Service...
Keywords:
Status: NEW
Alias: CVE-2026-27889
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2451496
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-25 20:02 UTC by OSIDB Bzimport
Modified: 2026-03-25 21:17 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-25 20:02:21 UTC
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server.  This happens before authentication, and so is exposed to anyone who can connect to the websockets port. Versions 2.11.14 and 2.12.5 contains a fix. A workaround is available. The vulnerability only affects deployments which use WebSockets and which expose the network port to untrusted end-points. If one is able to do so, a defense in depth of restricting either of these will mitigate the attack.


Note You need to log in before you can comment on or make changes to this bug.