<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:51:32.288049+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-nats-2026-29785</id>
    <title>BIT-nats-2026-29785 — NATS Server panic via malicious compression on leafnode port</title>
    <updated>2026-10-03T18:51:32.334574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: nats</p>
<p>NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-nats-2026-29785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0406</id>
    <title>certfr-2026-avi-0406 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-03T18:51:32.334631+00:00</updated>
    <content>certfr-2026-avi-0406</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0406"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-365478</id>
    <title>EUVD-2026-365478</title>
    <updated>2026-10-03T18:51:32.334653+00:00</updated>
    <content>EUVD-2026-365478</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-365478"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29785</id>
    <title>fkie_cve-2026-29785</title>
    <updated>2026-10-03T18:51:32.334665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-29785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-52jh-2xxh-pwh6</id>
    <title>GHSA-52jh-2xxh-pwh6 — NATS Server panic via malicious compression on leafnode port</title>
    <updated>2026-10-03T18:51:32.334689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/nats-io/nats-server/v2, Go: github.com/nats-io/nats-server</p>
<p>### Background</p>
<p>NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.</p>
<p>When configured to accept leafnode connections (for a hub/spoke topology of multiple nats-servers), then the default configuration allows for negotiating compression; a malicious remote NATS server can trigger a server panic via that compression.</p>
<p>### Problem Description</p>
<p>If the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used).</p>
<p>Context: a NATS server can form various clustering topologies, including local clusters, and superclusters of clusters, but leafnodes allow for separate administrative domains to link together with limited data communication; eg, a server in a moving vehicle might use a local leafnode for agents to connect to, and sync up to a central service as and when available. The leafnode configuration here is where the central server allows other NATS servers to connect into it, almost like regular NATS clients. Documentation examples typically use port 7422 for leafnode communications.</p>
<p>### Affected Versions</p>
<p>Version 2, prior to v2.11.14 or v2.12.5</p>
<p>### Workarounds</p>
<p>Disable compression on the leafnode port:</p>
<p>```
leafnodes {
  port: 7422
  compression: off
}
```</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-52jh-2xxh-pwh6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-29785</id>
    <title>msrc_CVE-2026-29785 — NATS Server panic via malicious compression on leafnode port</title>
    <updated>2026-10-03T18:51:32.334730+00:00</updated>
    <content>msrc_CVE-2026-29785</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-29785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:21769</id>
    <title>RHSA-2026:21769 — Red Hat Security Advisory: Multicluster Global Hub 1.5.4 security update</title>
    <updated>2026-10-03T18:51:32.334747+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana/tempo: Tempo: Denial of Service via large queries net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 github.com/nats-io/nats-server: NATS-Server: Denial of Service via malformed WebSockets frame github.com/nats-io/nats-server: NATS-Server: Denial of Service via leafnode compression crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation nats-server: NATS-Server: Session and message hijacking via MQTT Client ID malfeasance nats-server: github.com/nats-io/nats-server: NATS-Server: Information disclosure of MQTT passwords through monitoring endpoints nats-server: github.com/nats-io/nats-server: NATS-Server: Access control bypass via unapplied ACLs in MQTT namespace nats-server: github.com/nats-io/nats-server: NATS-Server: Denial of Service via mal…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:21769"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29785</id>
    <title>UBUNTU-CVE-2026-29785</title>
    <updated>2026-10-03T18:51:32.334824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: nats-server, Ubuntu:25.10: nats-server, Ubuntu:Pro:26.04:LTS: nats-server</p>
<p>NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0641</id>
    <title>WID-SEC-W-2026-0641 — NATS Server: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T18:51:32.334850+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in NATS Server ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0641"/>
  </entry>
</feed>
