High [CVE-2026-58250] Denial of Service via repeated leafnode INFO messages during pre-authentication
This high-severity Red Hat Linux advisory covers CVE-2026-58250.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system.
Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode INFO protocol messages before authentication and account setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.
This leads to a Denial of Service (DoS), making the server unavailable to legitimate users. This is an Important denial of service vulnerability in NATS Server.
Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476.
Red Hat lists Red Hat Hardened Images as not affected.
- < 2.12.8
- < 2.11.17
Official advisory · high-confidence parse· fetched 10 days ago·verify at source
- 2.12.8
- 2.11.17
Official advisory · high-confidence parse· fetched 10 days ago·verify at source
Mitigation checklist
- To reduce exposure, disable compression on NATS Server leafnode listeners if not strictly required for your environment. Alternatively, implement network access controls to restrict connectivity to leafnode listeners to only trusted clients. This limits the ability of unauthenticated peers to initiate the vulnerable handshake.
Official advisory · high-confidence parse· fetched 10 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.