—
GO-2026-4533
nats-server websockets are vulnerable to pre-auth memory DoS in github.com/nats-io/nats-server
Quick fix
GO-2026-4533 — github.com/nats-io/nats-server/v2: upgrade to the fixed version with the command below.
go get github.com/nats-io/nats-server/v2@v2.11.12Details
nats-server websockets are vulnerable to pre-auth memory DoS in github.com/nats-io/nats-server
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/nats-io/nats-server
Introduced in:
0No fixed version published yet for github.com/nats-io/nats-server (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/nats-io/nats-server/v2
Introduced in:
0Fixed in: 2.11.12Fix
go get github.com/nats-io/nats-server/v2@v2.11.12References
- https://github.com/nats-io/nats-server/security/advisories/GHSA-qrvq-68c2-7grw[ADVISORY]
- https://github.com/nats-io/nats-server/commit/f77fb7c4535e6727cc1a2899cd8e6bbdd8ba2017[FIX]
- https://github.com/nats-io/nats-server/releases/tag/v2.11.12[WEB]
- https://github.com/nats-io/nats-server/releases/tag/v2.12.3[WEB]