<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:54:40.781169+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-nats-2026-27571</id>
    <title>BIT-nats-2026-27571 — nats-server websockets are vulnerable to pre-auth memory DoS</title>
    <updated>2026-10-04T02:54:40.841514+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: nats</p>
<p>NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation bound the memory size of a NATS message but did not independently bound the memory consumption of the memory stream when constructing a NATS message which might then fail validation for size reasons. An attacker can use a compression bomb to cause excessive memory consumption, often resulting in the operating system terminating the server process. The use of compression is negotiated before authentication, so this does not require valid NATS credentials to exploit. The fix, present in versions 2.11.2 and 2.12.3, was to bounds the decompression to fail once the message was too large, instead of continuing on. The vulnerability only affects deployments which use WebSockets and which expose the network port to untrusted end-points.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-nats-2026-27571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0228</id>
    <title>certfr-2026-avi-0228 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-04T02:54:40.841576+00:00</updated>
    <content>certfr-2026-avi-0228</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0228"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-273594</id>
    <title>EUVD-2026-273594</title>
    <updated>2026-10-04T02:54:40.841597+00:00</updated>
    <content>EUVD-2026-273594</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-273594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27571</id>
    <title>fkie_cve-2026-27571</title>
    <updated>2026-10-04T02:54:40.841609+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation bound the memory size of a NATS message but did not independently bound the memory consumption of the memory stream when constructing a NATS message which might then fail validation for size reasons. An attacker can use a compression bomb to cause excessive memory consumption, often resulting in the operating system terminating the server process. The use of compression is negotiated before authentication, so this does not require valid NATS credentials to exploit. The fix, present in versions 2.11.2 and 2.12.3, was to bounds the decompression to fail once the message was too large, instead of continuing on. The vulnerability only affects deployments which use WebSockets and which expose the network port to untrusted end-points.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qrvq-68c2-7grw</id>
    <title>GHSA-qrvq-68c2-7grw — nats-server websockets are vulnerable to pre-auth memory DoS</title>
    <updated>2026-10-04T02:54:40.841635+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/nats-io/nats-server/v2, Go: github.com/nats-io/nats-server</p>
<p>### Impact</p>
<p>The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression.  The implementation bound the memory size of a NATS message but did not independently bound the memory consumption of the memory stream when constructing a NATS message which might then fail validation for size reasons.</p>
<p>An attacker can use a compression bomb to cause excessive memory consumption, often resulting in the operating system terminating the server process.</p>
<p>The use of compression is negotiated before authentication, so this does not require valid NATS credentials to exploit.</p>
<p>The fix was to bounds the decompression to fail once the message was too large, instead of continuing on.</p>
<p>### Patches</p>
<p>This was released in nats-server without being highlighted as a security issue.  It should have been, this was an oversight.  Per the NATS security policy, because this does not require a valid user, it is CVE-worthy.</p>
<p>This was fixed in the v2.11 series with v2.11.12 and in the v2.12 series with v2.12.3.</p>
<p>### Workarounds</p>
<p>This only affects deployments which use WebSockets and which expose the network port to untrusted end-points.</p>
<p>### References</p>
<p>This was reported to the NATS maintainers by Pavel Kohout of Aisle Research (www.aisle.com).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qrvq-68c2-7grw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-27571</id>
    <title>msrc_CVE-2026-27571 — nats-server websockets are vulnerable to pre-auth memory DoS</title>
    <updated>2026-10-04T02:54:40.841675+00:00</updated>
    <content>msrc_CVE-2026-27571</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-27571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:5110</id>
    <title>RHSA-2026:5110 — Red Hat Security Advisory: Multicluster Global Hub 1.5.4 security update</title>
    <updated>2026-10-04T02:54:40.841693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 nats-server: WebSockets pre-auth memory DoS</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:5110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27571</id>
    <title>UBUNTU-CVE-2026-27571</title>
    <updated>2026-10-04T02:54:40.841720+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: nats-server, Ubuntu:25.10: nats-server, Ubuntu:Pro:26.04:LTS: nats-server</p>
<p>NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation bound the memory size of a NATS message but did not independently bound the memory consumption of the memory stream when constructing a NATS message which might then fail validation for size reasons. An attacker can use a compression bomb to cause excessive memory consumption, often resulting in the operating system terminating the server process. The use of compression is negotiated before authentication, so this does not require valid NATS credentials to exploit. The fix, present in versions 2.11.2 and 2.12.3, was to bounds the decompression to fail once the message was too large, instead of continuing on. The vulnerability only affects deployments which use WebSockets and which expose the network port to untrusted end-points.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0487</id>
    <title>WID-SEC-W-2026-0487 — NATS Server: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-04T02:54:40.841747+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in NATS Server ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0487"/>
  </entry>
</feed>
