CVE-2026-58207: NATS Server: Remote crash via integer overflow in Connz pagination
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the response window was safely bounded. This issue is fixed in versions 2.14.3 and 2.12.12.
Other sources
NATS Server: Remote crash via integer overflow in Connz pagination
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.31.0-24 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.14.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.12.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58207?
The severity of CVE-2026-58207 is high, with a score of 7.7 according to the CVSS v3.1 metrics.
How do I fix CVE-2026-58207?
To fix CVE-2026-58207, upgrade the NATS Server to version 2.14.3 or later, or 2.12.12 or later.
What causes the CVE-2026-58207 vulnerability?
CVE-2026-58207 is caused by an integer overflow that can occur when handling Connz pagination Offset and Limit values in NATS Server.
Can CVE-2026-58207 lead to a denial of service?
Yes, CVE-2026-58207 can lead to a denial of service by crashing the NATS Server when exploited.
Which versions of NATS Server are affected by CVE-2026-58207?
CVE-2026-58207 affects NATS Server versions prior to 2.14.3 and 2.12.12.