CVE-2020-26521: Null Pointer Dereference
The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-26521?
CVE-2020-26521 is a vulnerability in the JWT library in NATS nats-server before version 2.1.9 that allows a denial of service through a nil dereference in Go code.
What is the severity of CVE-2020-26521?
The severity of CVE-2020-26521 is high, with a CVSS score of 7.5.
Which software is affected by CVE-2020-26521?
The Linuxfoundation NATS nats-server version up to exclusive 2.1.9 and Fedora 33 are affected by CVE-2020-26521.
How can I fix the CVE-2020-26521 vulnerability?
To fix the CVE-2020-26521 vulnerability, update the NATS nats-server to version 2.1.9 or later.
Where can I find more information about CVE-2020-26521?
You can find more information about CVE-2020-26521 at the following references: [1] http://www.openwall.com/lists/oss-security/2020/11/02/2, [2] https://github.com/nats-io/nats-server/commits/master, [3] https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VT67XCLIIBYRT762SVFBYFFTQFVSM3SI/