THREAT OPS › Threat News
Threat Intelligence News
12175 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [Breach] LegionProxy — 10,144 accounts exposedhibp_breaches · 2026-04-06
- Elastic Security Integrations Roundup: Q1 2026elastic_security · 2026-04-04
- [NVD] CVE-2026-3184 (LOW 3.7) — A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potnvd · 2026-04-03
- [NVD] CVE-2026-0545 (CRITICAL 9.8) — In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_nvd · 2026-04-03
- [NVD] CVE-2026-23459 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which call iptunnel_xmit_stats(). iptunnel_xmit_stats() was assuming tunnenvd · 2026-04-03
- [NVD] CVE-2026-23448 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check cdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE entries fit within the skb. The first check correctly accounts for ndpoffset: nvd · 2026-04-03
- [NVD] CVE-2026-23447 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated against tnvd · 2026-04-03
- Simplifying MBA obfuscation with CoBRAtrailofbits · 2026-04-03
- [Breach] Amtrak — 2,147,679 accounts exposedhibp_breaches · 2026-04-03
- Cisco IOS XE Software Denial of Service Vulnerabilitycisco_psirt · 2026-04-02
- [NVD] CVE-2026-34118 (MEDIUM 6.5) — A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling externallnvd · 2026-04-02
- ghostsurf: From NTLM Relay to Browser Session Hijackingspecterops · 2026-04-02
- Google Workspace’s continuous approach to mitigating indirect prompt injectionsgoogle_security · 2026-04-02
- vSphere and BRICKSTORM Malware: A Defender's Guidemandiant_gti · 2026-04-02
- You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)watchtowr · 2026-04-02
- The Invisible Army: Why IP Reputation Fails Against the Rotation Economygreynoise_blog · 2026-04-02
- Overview of Content Published in Marchdidier_stevens · 2026-04-02
- [Breach] SongTrivia2 — 291,739 accounts exposedhibp_breaches · 2026-04-02
- Prioritizing Alerts Triage with Higher-Order Detection Ruleselastic_security · 2026-04-02
- [NVD] CVE-2026-20097 (MEDIUM 6.5) — A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based mnvd · 2026-04-01
- [NVD] CVE-2026-20096 (MEDIUM 6.5) — A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is dnvd · 2026-04-01
- [NVD] CVE-2026-20095 (MEDIUM 6.5) — A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is dnvd · 2026-04-01
- [NVD] CVE-2026-20094 (HIGH 8.8) — A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to invd · 2026-04-01
- [NVD] CVE-2026-20090 (MEDIUM 4.8) — A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. Anvd · 2026-04-01
- [NVD] CVE-2026-20089 (MEDIUM 4.8) — A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. Anvd · 2026-04-01
- [NVD] CVE-2026-20088 (MEDIUM 4.8) — A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. Anvd · 2026-04-01
- [NVD] CVE-2026-20087 (MEDIUM 4.8) — A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. Anvd · 2026-04-01
- [NVD] CVE-2026-20085 (MEDIUM 6.1) — A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit tnvd · 2026-04-01
- Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerabilitycisco_psirt · 2026-04-01
- Cisco Evolved Programmable Network Manager Improper Authorization Vulnerabilitycisco_psirt · 2026-04-01
- Ludus SCCM Lab Expansionspecterops · 2026-04-01
- [NVD] CVE-2026-35092 (HIGH 7.5) — A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vnvd · 2026-04-01
- [NVD] CVE-2026-35091 (HIGH 8.2) — A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing nvd · 2026-04-01
- Mutation testing for the agentic eratrailofbits · 2026-04-01
- [NVD] CVE-2026-4374 (CRITICAL 9.1) — Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowunvd · 2026-04-01
- [NVD] CVE-2026-2394 (MEDIUM 6.5) — Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2nvd · 2026-04-01
- Elastic releases detections for the Axios supply chain compromiseelastic_security · 2026-04-01
- [NVD] CVE-2026-1579 (CRITICAL 9.8) — The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with accesnvd · 2026-03-31
- [NVD] CVE-2026-4800 (HIGH 8.1) — Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an anvd · 2026-03-31
- Expanding Attack Path Management to macOS Environmentsspecterops · 2026-03-31
- VRP 2025 Year in Reviewgoogle_security · 2026-03-31
- North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attackmandiant_gti · 2026-03-31
- How we made Trail of Bits AI-native (so far)trailofbits · 2026-03-31
- [NVD] CVE-2026-34881 (MEDIUM 5.0) — OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affectednvd · 2026-03-31
- [NVD] CVE-2026-34070 (HIGH 7.5) — LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injnvd · 2026-03-31
- [NVD] CVE-2026-33997 (MEDIUM 6.8) — Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrenvd · 2026-03-31
- [Breach] Hallmark — 1,736,520 accounts exposedhibp_breaches · 2026-03-31
- [NVD] CVE-2026-21717 (MEDIUM 5.9) — A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade perfonvd · 2026-03-30
- [NVD] CVE-2026-21716 (LOW 3.3) — An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `nvd · 2026-03-30
- [NVD] CVE-2026-21715 (LOW 3.3) — A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fsnvd · 2026-03-30
- [NVD] CVE-2026-21714 (MEDIUM 5.3) — A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned nvd · 2026-03-30
- [NVD] CVE-2026-21713 (MEDIUM 5.9) — A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possiblnvd · 2026-03-30
- [NVD] CVE-2026-21711 (MEDIUM 5.3) — A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can nvd · 2026-03-30
- [NVD] CVE-2026-21710 (HIGH 7.5) — A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, cnvd · 2026-03-30
- GitHub for Beginners: Getting started with GitHub securitygithub_security_lab · 2026-03-30
- [NVD] CVE-2026-4315 (MEDIUM 6.5) — A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page.nvd · 2026-03-30
- [NVD] CVE-2026-4266 (MEDIUM 6.7) — An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. Note, this vulnerability does not affect Firenvd · 2026-03-30
- [NVD] CVE-2026-3945 (HIGH 7.5) — An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol without nvd · 2026-03-30
- [NVD] CVE-2025-15379 (CRITICAL 10.0) — A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact'snvd · 2026-03-30
- Cloudflare Client-Side Security: smarter detection, now open to everyonecloudflare_security · 2026-03-30
- TSUBAME Report Overflow (Jul-Sep 2025)jpcert_blog · 2026-03-30
- [NVD] CVE-2026-4946 (HIGH 8.8) — Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the @execute annotation (which is intended for trusted, user-autnvd · 2026-03-29
- Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)watchtowr · 2026-03-29
- [Breach] Paidwork — 23,272,765 accounts exposedhibp_breaches · 2026-03-29
- The Sequels Are Never As Good, But We're Still In Pain (Citrix NetScaler CVE-2026-3055 Memory Overread)watchtowr · 2026-03-28
- [NVD] CVE-2026-23399 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expression memleak in error path If cloning the second stateful expression in the element via GFP_ATOMIC fails, then the first stateful expression remains in place wnvd · 2026-03-28
- [NVD] CVE-2026-33941 (HIGH 8.2) — Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly invd · 2026-03-27
- [NVD] CVE-2026-33940 (HIGH 8.1) — Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all conditional guards in `resolvePartial()` and cause `invokePartial()` to return `undefined`. The Handlebarnvd · 2026-03-27
- [NVD] CVE-2026-33939 (HIGH 7.5) — Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the compiled template calls `lookupProperty(decorators, "n")nvd · 2026-03-27
- [NVD] CVE-2026-33938 (HIGH 8.1) — Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data context and is reachable and mutable from within a template via helpers that accept arbitrary objecnvd · 2026-03-27
- [NVD] CVE-2026-33937 (CRITICAL 9.8) — Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLiteral` AST node is emitted directly into the genvd · 2026-03-27
- [NVD] CVE-2026-33896 (HIGH 7.4) — Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints`nvd · 2026-03-27
- [NVD] CVE-2026-33895 (HIGH 7.5) — Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signanvd · 2026-03-27
- [NVD] CVE-2026-33894 (HIGH 7.5) — Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing “garbanvd · 2026-03-27
- [NVD] CVE-2026-33891 (HIGH 7.5) — Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from nvd · 2026-03-27
- [NVD] CVE-2026-33871 (HIGH 7.5) — Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit onvd · 2026-03-27
- [NVD] CVE-2026-33870 (HIGH 7.5) — Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final annvd · 2026-03-27
- [NVD] CVE-2026-28369 (HIGH 8.7) — A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attanvd · 2026-03-27
- [NVD] CVE-2026-28368 (HIGH 8.7) — A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggnvd · 2026-03-27
- [NVD] CVE-2026-28367 (HIGH 8.7) — A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Applicationnvd · 2026-03-27
- [NVD] CVE-2026-4984 (HIGH 8.2) — The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' parameters) using HTTP requests that include the integration's Twilio credentials in thenvd · 2026-03-27
- [NVD] CVE-2026-4948 (MEDIUM 5.5) — A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper anvd · 2026-03-27
- [Breach] ZenBusiness — 5,118,184 accounts exposedhibp_breaches · 2026-03-27
- [NVD] CVE-2026-2100 (MEDIUM 5.3) — A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitializenvd · 2026-03-26
- [NVD] CVE-2026-0968 (LOW 3.1) — A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory nvd · 2026-03-26
- [NVD] CVE-2026-0967 (MEDIUM 5.5) — A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts andnvd · 2026-03-26
- [NVD] CVE-2026-0966 (HIGH 8.2) — A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server'nvd · 2026-03-26
- [NVD] CVE-2026-0965 (LOW 3.3) — A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by cnvd · 2026-03-26
- [NVD] CVE-2026-0964 (MEDIUM 6.3) — A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. Thisnvd · 2026-03-26
- [NVD] CVE-2026-4926 (HIGH 7.5) — Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service. Patches: Fixed in version 8.4.0. Worknvd · 2026-03-26
- [NVD] CVE-2026-33487 (HIGH 7.5) — goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID. In Go versions before 1.22, or when `go.monvd · 2026-03-26
- [NVD] CVE-2026-4897 (MEDIUM 5.5) — A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of nvd · 2026-03-26
- [NVD] CVE-2026-4809 (CRITICAL 9.8) — plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executablnvd · 2026-03-26
- Introducing Intelligence Center 3.7: Faster decisions with clearer context across defense and enterpriseeclecticiq · 2026-03-26
- Free TIP Bundles to test, validate, and operationalize threat intelligence fastereclecticiq · 2026-03-26
- [Breach] BreachForums Version 5 — 339,778 accounts exposedhibp_breaches · 2026-03-26
- [NVD] CVE-2026-33247 (HIGH 7.4) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any usnvd · 2026-03-25
- [NVD] CVE-2026-33219 (MEDIUM 5.3) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requiresnvd · 2026-03-25
- [NVD] CVE-2026-33218 (HIGH 7.5) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 annvd · 2026-03-25
- [NVD] CVE-2026-33217 (HIGH 7.1) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT snvd · 2026-03-25