THREAT OPS › Threat News › [NVD] CVE-2026-33219 (MEDIUM 5.3) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires
[NVD] CVE-2026-33219 (MEDIUM 5.3) — NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires
CVE-2026-33219 CVSS: 5.3 MEDIUM Published: 2026-03-25T20:16:32.777
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a m
MITRE ATT&CK techniques
- CompressionT1027.015
Indicators of compromise
- CVE-2026-33219cve
- CVE-2026-27571cve
- nats.iodomain
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-33219