
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33218 is a pre-authentication Denial of Service vulnerability in NATS-Server, the high-performance messaging server for NATS.io. A remote, unauthenticated client that can connect to the leafnode port can crash the server by sending a specific malformed message before completing authentication. All versions prior to 2.11.15 and 2.12.6 (including the 2.12.x release candidates) are affected. The vulnerability was published on March 24, 2026, with a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is improper input validation (CWE-20, CWE-1286) in the leafnode connection handling code of nats-server. The leafnode feature enables hub/spoke topologies by allowing other NATS servers to connect as leaf nodes; the server fails to properly validate syntactically malformed messages received before the authentication handshake completes, leading to a server panic (crash). No authentication or special privileges are required — any network client able to reach the leafnode port can trigger the crash with a crafted message (GitHub Advisory, NATS Advisory).
Successful exploitation results in a complete crash (panic) of the nats-server process, causing a full loss of availability for all messaging services dependent on that server instance. There is no impact on confidentiality or data integrity, as the attack occurs pre-authentication and does not grant the attacker access to messages or data. In environments where NATS serves as critical messaging infrastructure (cloud, IoT, edge computing), repeated exploitation could cause sustained service outages and disrupt dependent applications (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.066% (21st percentile), indicating a currently low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of authentication requirements make it straightforward to exploit for any attacker with network access to the leafnode port (GitHub Advisory).
nats-server process; automated restart events (e.g., systemd service restarts) correlated with inbound connections to the leafnode port./var/log/syslog or journalctl) for the nats-server service, particularly if correlated with external connection attempts (GitHub Advisory).Upgrade nats-server to version 2.11.15 or 2.12.6, which contain the fix for this vulnerability (GitHub Advisory, NATS Advisory). If upgrading immediately is not possible, apply one of the following workarounds:
The vulnerability was published by NATS maintainer philpennock via the official GitHub Security Advisory on March 24, 2026, and was subsequently tracked by Red Hat's Product Security team in Bugzilla. OpenSUSE issued a security announcement for the affected package, and the vulnerability was picked up by security aggregators including VulnDB, CVEFeed, and LinuxSecurity. Social media coverage was limited but present on Mastodon and Bluesky, with security community accounts sharing the advisory shortly after publication (GitHub Advisory, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
devel
nats-server
noble
nats-server
noble (esm-apps)
nats-server
resolute
nats-server
resolute (esm-apps)
nats-server
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."