github.com/nats-io/nats-server/v2 vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-27889Highgithub.com/nats-io/nats-server/v2: NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsReadCVE-2026-33248Mediumgithub.com/nats-io/nats-server/v2: NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matchingCVE-2026-33246Mediumgithub.com/nats-io/nats-server/v2: NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headersCVE-2026-33223Mediumgithub.com/nats-io/nats-server/v2: NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity SpoofingCVE-2026-33222Mediumgithub.com/nats-io/nats-server/v2: NATS JetStream has an authorization bypass through its Management APICVE-2026-33219Mediumgithub.com/nats-io/nats-server/v2: NATS is vulnerable to pre-auth DoS through WebSockets client serviceCVE-2026-33218Highgithub.com/nats-io/nats-server/v2: NATS has pre-auth server panic via leafnode handlingCVE-2026-33217Highgithub.com/nats-io/nats-server/v2: NATS allows MQTT clients to bypass ACL checksCVE-2026-33216Highgithub.com/nats-io/nats-server/v2: NATS has MQTT plaintext password disclosureCVE-2026-33215Mediumgithub.com/nats-io/nats-server/v2: NATS is vulnerable to MQTT hijacking via Client IDCVE-2026-29785Highgithub.com/nats-io/nats-server/v2: NATS Server panic via malicious compression on leafnode portCVE-2026-33247Highgithub.com/nats-io/nats-server/v2: NATS credentials are exposed in monitoring port via command-line argvCVE-2026-33249Mediumgithub.com/nats-io/nats-server/v2: NATS: Message tracing can be redirected to arbitrary subjectCVE-2026-27571Mediumgithub.com/nats-io/nats-server/v2: nats-server websockets are vulnerable to pre-auth memory DoSCVE-2025-30215Criticalgithub.com/nats-io/nats-server/v2: NATS Server may fail to authorize certain Jetstream admin APIsCVE-2022-29946Highgithub.com/nats-io/nats-server/v2: NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied…CVE-2021-32026Lowgithub.com/nats-io/nats-server/v2: NATS server TLS missing ciphersuite settings when CLI flags usedCVE-2023-46129Highgithub.com/nats-io/nkeys: xkeys seal encryption used fixed key for all encryptionCVE-2023-47090Highgithub.com/nats-io/nats-server/v2: NATS.io: Adding accounts for just the system account adds auth bypassCVE-2022-26652Highgithub.com/nats-io/nats-server/v2: Arbitrary file write in nats-serverCVE-2020-28466Highgithub.com/nats-io/nats-server: Denial of service in github.com/nats-io/nats-server/serverCVE-2022-24450Highgithub.com/nats-io/nats-streaming-server: Incorrect Authorization in NATS nats-serverGHSA-J756-F273-XHP4Highgithub.com/nats-io/nats-server/v2: github.com/nats-io/nats-server Import token permissions checking not enforcedGHSA-GWJ5-3VFQ-Q992Lowgithub.com/nats-io/nats-server/v2: Import loops in account imports, nats-server DoSGHSA-HMM9-R2M2-QG9WHighgithub.com/nats-io/nats-server/v2: Nil dereference in NATS JWT causing DoS of nats-server

Stop the waste.
Protect your environment with Kodem.