CVE-2026-29785 describes a high-severity denial-of-service vulnerability affecting NATS-Server versions prior to 2.11.14 and 2.12.5. This flaw allows an unauthenticated attacker to crash the server by triggering a panic, provided the non-default "leafnode" configuration is enabled and compression (default for leafnodes) is active. Rated 7.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), it requires no privileges or user interaction and has a network attack vector, leading to a complete loss of availability. While it is on a "Hot List," there is currently no evidence of active exploitation in the wild (KEV: No), nor is public exploit code available. Community discussion is present, and the vulnerability is addressed in versions 2.11.14 and 2.12.5, with disabling leafnode compression serving as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.14CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* | ||
>= 2.12.0, < 2.12.5CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.