CVE-2026-58208: NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.
Other sources
NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.31.0-24 - Upgrade
Upgrade
NATS Serverto a version that resolves this vulnerability.Fixed in 2.14.3 - Upgrade
Upgrade
NATS Serverto a version that resolves this vulnerability.Fixed in 2.12.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58208?
CVE-2026-58208 has a severity rating of high at 7.5.
How do I fix CVE-2026-58208?
To fix CVE-2026-58208, upgrade to NATS Server versions 2.14.3 or 2.12.12 and above.
What impact does CVE-2026-58208 have on my NATS Server?
CVE-2026-58208 can cause WebSocket-only JetStream servers to crash if MQTT requests are improperly routed.
Who is affected by CVE-2026-58208?
NATS Server users running versions prior to 2.14.3 and 2.12.12 are affected by CVE-2026-58208.
What kind of vulnerability is CVE-2026-58208?
CVE-2026-58208 is a vulnerability that allows unauthenticated clients to potentially crash the server.