CVE-2026-27889 is a high-severity denial-of-service vulnerability affecting NATS-Server versions 2.2.0 through 2.11.13 and 2.12.4, stemming from a missing sanity check on WebSockets frames. This flaw, rated CVSS 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), allows an unauthenticated attacker to remotely trigger a server panic via the network, resulting in a complete loss of availability for affected deployments utilizing WebSockets. Although no public exploit code or active exploitation is confirmed (not in KEV), the vulnerability is on a "Hot List" and has generated community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, < 2.11.14CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* | ||
>= 2.12.0, < 2.12.5CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.