Skip to content
VulniPulse
High7.5Red Hat Linux

High [CVE-2026-58250] Denial of Service via repeated leafnode INFO messages during pre-authentication

This high-severity Red Hat Linux advisory covers CVE-2026-58250.

CVE-2026-58250 Published Jul 8, 2026Updated by vendor Jul 8, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system.

Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode INFO protocol messages before authentication and account setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.

This leads to a Denial of Service (DoS), making the server unavailable to legitimate users. This is an Important denial of service vulnerability in NATS Server.

Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476.

Red Hat lists Red Hat Hardened Images as not affected.

Affected versions
  • < 2.12.8
  • < 2.11.17

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Fixed versions
  • 2.12.8
  • 2.11.17

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To reduce exposure, disable compression on NATS Server leafnode listeners if not strictly required for your environment. Alternatively, implement network access controls to restrict connectivity to leafnode listeners to only trusted clients. This limits the ability of unauthenticated peers to initiate the vulnerable handshake.

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.