CVE-2026-33218 is a high-severity vulnerability (CVSS 7.5) affecting NATS-Server versions prior to 2.11.15 and 2.12.6. An unauthenticated attacker can remotely crash the server by sending a malformed message to the leafnode port, leading to a denial of service. The attack requires no privileges or user interaction and has low complexity. While there are no known public exploits or KEV entries, the vulnerability is on the Hot List and has garnered significant community discussion, indicating potential future exploitation. Organizations should update to patched versions or implement the recommended workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.15CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* | ||
>= 2.12.0, < 2.12.6CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.