pkg:Bitnami/nats
20 total CVEsCRITICAL1HIGH10MEDIUM9
✅ Check your installed version
All known vulnerabilities
- CRITICAL9.6CVE-2025-30215Missing ACLs on JavaScript APIs allowing privilege escalation github.com/nats-io/nats-server>= 2.2.0, < 2.11.1
- >= 2.0.0, < 2.7.2
- from 0, < 2.11.15, >= 2.12.0, < 2.12.6
- HIGH7.5CVE-2026-27889NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead>= 2.2.0, < 2.11.14, >= 2.12.0, < 2.12.5
- from 0, < 2.11.15, >= 2.12.0, < 2.12.6
- HIGH7.5CVE-2026-29785NATS Server panic via malicious compression on leafnode port in github.com/nats-io/nats-serverfrom 0, < 2.11.14, >= 2.12.0, < 2.12.5
- >= 2.10.0, < 2.10.4
- >= 2.0.0, < 2.2.0
- >= 2.0.0, < 2.2.0
- from 0, < 2.11.15, >= 2.12.0, < 2.12.6
- from 0, < 2.11.15, >= 2.12.0, < 2.12.6
- from 0, < 2.11.15, >= 2.12.0, < 2.12.6
- >= 2.2.0, < 2.7.4
- MEDIUM6.4CVE-2026-33246NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headersfrom 0, < 2.11.15, >= 2.12.0, < 2.12.6
- MEDIUM6.4CVE-2026-33223NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofingfrom 0, < 2.11.15, >= 2.12.0, < 2.12.6
- from 0, < 2.11.12, >= 2.12.0, < 2.12.3
- from 0, < 2.11.15, >= 2.12.0, < 2.12.6
- from 0, < 2.11.15, >= 2.12.0, < 2.12.6
- >= 2.11.0, < 2.11.15, >= 2.12.0, < 2.12.6
- MEDIUM4.2CVE-2026-33248NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matchingfrom 0, < 2.11.15, >= 2.12.0, < 2.12.6