—
GO-2026-4831
NATS is vulnerable to pre-auth DoS through WebSockets client service in github.com/nats-io/nats-server
Quick fix
GO-2026-4831 — github.com/nats-io/nats-server/v2: upgrade to the fixed version with the command below.
go get github.com/nats-io/nats-server/v2@v2.11.15Details
NATS is vulnerable to pre-auth DoS through WebSockets client service in github.com/nats-io/nats-server
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/nats-io/nats-server
Introduced in:
0No fixed version published yet for github.com/nats-io/nats-server (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/nats-io/nats-server/v2
Introduced in:
0Fixed in: 2.11.15Fix
go get github.com/nats-io/nats-server/v2@v2.11.15