Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

0Xasritha

#22529of 56,335
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-56559
4.3
2026-07-08
Unknown · Nats Server · CVE-2026-58209
**Name of the Vulnerable Software and Affected Versions** NATS Server versions prior to 2.14.3 NATS Server versions prior to 2.12.12 **Description** MQTT retained message delivery and QoS1+ durable replay may deliver messages to subscribers even if the original topics match a configured subscribe deny rule. This occurs because the delivery paths fail to consistently recheck the concrete original topic before sending the MQTT PUBLISH message to the subscriber. **Recommendations** Update NATS Server to version 2.14.3 or later. Update NATS Server to version 2.12.12 or later.
PT-2026-56560
7.5
2026-07-08
Unknown · Nats Server · CVE-2026-58210
**Name of the Vulnerable Software and Affected Versions** NATS Server versions prior to 2.14.3 NATS Server versions prior to 2.12.12 **Description** An unauthenticated MQTT client can cause the server to consume excessive memory by sending large incomplete MQTT CONNECT packets. The server retains these packets while the parser waits for the advertised packet length to be completed before authentication is finalized, leading to memory exhaustion. **Recommendations** Update NATS Server to version 2.14.3. Update NATS Server to version 2.12.12.