LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-58207

linuxfoundation · nats-server

Published
CVSS7.7
Severityhigh
WeaknessCWE-190
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Description

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the response window was safely bounded. This issue is fixed in versions 2.14.3 and 2.12.12.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-58207

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-58207.