CVE-2026-58210: NATS Server: MQTT partial CONNECT packets can exhaust pre-auth memory
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQTT client could cause the server to retain large incomplete MQTT CONNECT packets before authentication completed, consuming server memory while the parser waited for the advertised MQTT packet length. This issue is fixed in versions 2.14.3 and 2.12.12.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58210?
CVE-2026-58210 has a high severity rating of 7.5.
How do I fix CVE-2026-58210?
To fix CVE-2026-58210, upgrade to NATS Server version 2.14.3 or 2.12.12 or later.
What type of vulnerability is CVE-2026-58210?
CVE-2026-58210 is a memory exhaustion vulnerability caused by unauthenticated MQTT clients sending incomplete CONNECT packets.
What impact does CVE-2026-58210 have on NATS Server?
CVE-2026-58210 can lead to excessive memory consumption on the NATS Server before authentication is completed.
Who can be affected by CVE-2026-58210?
NATS Server deployments that allow unauthenticated MQTT clients are at risk from CVE-2026-58210.