CVE-2026-29785: NATS Server panic via malicious compression on leafnode port

Published Mar 24, 2026
·
Updated

Background

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.

When configured to accept leafnode connections (for a hub/spoke topology of multiple nats-servers), then the default configuration allows for negotiating compression; a malicious remote NATS server can trigger a server panic via that compression.

Problem Description

If the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used).

Context: a NATS server can form various clustering topologies, including local clusters, and superclusters of clusters, but leafnodes allow for separate administrative domains to link together with limited data communication; eg, a server in a moving vehicle might use a local leafnode for agents to connect to, and sync up to a central service as and when available. The leafnode configuration here is where the central server allows other NATS servers to connect into it, almost like regular NATS clients. Documentation examples typically use port 7422 for leafnode communications.

Affected Versions

Version 2, prior to v2.11.14 or v2.12.5

Workarounds

Disable compression on the leafnode port:

leafnodes { port: 7422 compression: off }

Other sources

NATS Server panic via malicious compression on leafnode port

Microsoft

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.

NVD

Affected Software

5 affected componentsFixes available
go/github.com/nats-io/nats-server/v2>=2.12.0-RC.1<2.12.5
2.12.5
go/github.com/nats-io/nats-server/v2<2.11.14
2.11.14
linuxfoundation Nats-server<2.11.14
linuxfoundation Nats-server>=2.12.0<2.12.5
Microsoft azl3 telegraf 1.31.0-17

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/nats-io/nats-server/v2 to a version that resolves this vulnerability.

    Fixed in 2.12.5
  2. Upgrade

    Upgrade go/github.com/nats-io/nats-server/v2 to a version that resolves this vulnerability.

    Fixed in 2.11.14
  3. Upgrade

    Upgrade NATS Server to a version that resolves this vulnerability.

    Fixed in 2.11.14
  4. Upgrade

    Upgrade NATS Server to a version that resolves this vulnerability.

    Fixed in 2.12.5
  5. Configuration

    As a workaround, disable compression on the leafnode port (example config: `compression: off` and leafnode `port: 7422`).

    NATS Server (leafnodes) compression = off

Event History

Mar 24, 2026
Advisory Published
via GitHub·09:29 PM
Data Sourced
via GitHub·09:29 PM
DescriptionSeverityWeaknessAffected Software
Mar 25, 2026
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·08:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 2, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:06 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-29785?

CVE-2026-29785 has been assessed with a severity that indicates a significant risk for users of affected NATS servers.

2

How do I fix CVE-2026-29785?

To fix CVE-2026-29785, upgrade to NATS Server version 2.12.5 or 2.11.14 as applicable.

3

What versions are affected by CVE-2026-29785?

CVE-2026-29785 affects NATS Server versions from 2.12.0-RC.1 up to 2.12.5 and all versions below 2.11.14.

4

What configurations are vulnerable in CVE-2026-29785?

CVE-2026-29785 vulnerabilities arise when NATS is configured to accept leafnode connections in a hub/spoke topology.

5

Is there a workaround for CVE-2026-29785 before upgrading?

There is no documented workaround for CVE-2026-29785, so upgrading to the latest version is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203