CVE-2026-58250: NATS Server: Pre-auth server crash via double INFO in leafnode handshake
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode INFO protocol messages before authentication and account setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.
Other sources
NATS Server: Pre-auth server crash via double INFO in leafnode handshake
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.31.0-24 - Upgrade
Upgrade
NATS Serverto a version that resolves this vulnerability.Fixed in 2.12.8 - Upgrade
Upgrade
NATS Serverto a version that resolves this vulnerability.Fixed in 2.11.17
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58250?
The severity of CVE-2026-58250 is rated high with a score of 7.5.
How do I fix CVE-2026-58250?
To fix CVE-2026-58250, upgrade to NATS Server version 2.12.8 or 2.11.17 or later.
What causes the vulnerability CVE-2026-58250?
CVE-2026-58250 is caused by a null pointer dereference during the pre-authentication leafnode handshake with an unauthenticated peer.
What impact does CVE-2026-58250 have on NATS Server?
CVE-2026-58250 can lead to a server crash, affecting the availability of the NATS Server.
Who is affected by CVE-2026-58250?
Users of NATS Server prior to versions 2.12.8 and 2.11.17 with compression enabled on the leafnode listener are affected by CVE-2026-58250.