CVE-2026-33218: NATS has pre-auth server panic via leafnode handling

Published Mar 24, 2026
·
Updated

Background

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.

The nats-server allows hub/spoke topologies using "leafnode" connections by other nats-servers.

Problem Description

A client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication.

Affected Versions

Any version before v2.12.6 or v2.11.15

Workarounds

1. Disable leafnode support if not needed. 2. Restrict network connections to your leafnode port, if plausible without compromising the service offered.

References

This document is canonically: <https://advisories.nats.io/CVE/secnote-2026-10.txt> GHSA advisory: <https://github.com/nats-io/nats-server/security/advisories/GHSA-vprv-35vv-q339> MITRE CVE entry: <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33218>

Other sources

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.

MITRE

Affected Software

4 affected componentsFixes available
go/github.com/nats-io/nats-server/v2>=2.12.0-RC.1<2.12.6
2.12.6
go/github.com/nats-io/nats-server/v2<2.11.15
2.11.15
linuxfoundation Nats-server<2.11.15
linuxfoundation Nats-server>=2.12.0<2.12.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/nats-io/nats-server/v2 to a version that resolves this vulnerability.

    Fixed in 2.12.6
  2. Upgrade

    Upgrade go/github.com/nats-io/nats-server/v2 to a version that resolves this vulnerability.

    Fixed in 2.11.15
  3. Upgrade

    Upgrade nats-server to a version that resolves this vulnerability.

    Fixed in 2.11.15
  4. Upgrade

    Upgrade nats-server to a version that resolves this vulnerability.

    Fixed in 2.12.6
  5. Configuration

    As a workaround, disable leafnode support if it is not needed (affected if running a version before v2.12.6 or v2.11.15).

    nats-server (leafnode) leafnode support = disabled
  6. Compensating control

    As a workaround, restrict network connections to the nats-server leafnode port, if plausible without compromising the service offered (affected if running a version before v2.12.6 or v2.11.15).

Event History

Mar 24, 2026
Advisory Published
via GitHub·09:45 PM
Data Sourced
via GitHub·09:45 PM
DescriptionSeverityWeaknessAffected Software
Mar 25, 2026
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·08:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-33218?

The severity of CVE-2026-33218 is classified as moderate.

2

How do I fix CVE-2026-33218?

To fix CVE-2026-33218, upgrade the nats-server to version 2.12.6 or 2.11.15.

3

What versions of nats-server are affected by CVE-2026-33218?

CVE-2026-33218 affects nats-server versions from 2.12.0-RC.1 up to but not including 2.12.6, and all versions prior to 2.11.15.

4

What type of vulnerability is CVE-2026-33218?

CVE-2026-33218 is a vulnerability related to insecure connection handling in nats-server.

5

Who is affected by CVE-2026-33218?

Users of nats-server versions within the specified ranges are affected by CVE-2026-33218.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203