Affected by GO-2022-0307
and 21 other vulnerabilities
GO-2022-0307: Incorrect Authorization in NATS nats-server in github.com/nats-io/nats-server
GO-2022-0351: Arbitrary file write in nats-server in github.com/nats-io/nats-server
GO-2022-0398: Import loops in account imports, nats-server DoS in github.com/nats-io/nats-server
GO-2022-0852: Integer Overflow or Wraparound in NATS Server in github.com/nats-io/nats-server
GO-2022-0855: Denial of service in github.com/nats-io/nats-server/server in github.com/nats-io/nats-server
GO-2023-2066: NATS nats-server allows directory traversal via unintended path to a management action in github.com/nats-io/nats-server
GO-2024-2850: NATS server TLS missing ciphersuite settings when CLI flags used in github.com/nats-io/nats-server
GO-2024-2980: NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjects in github.com/nats-io/nats-server
GO-2026-4533: nats-server websockets are vulnerable to pre-auth memory DoS in github.com/nats-io/nats-server
GO-2026-4826: NATS: Message tracing can be redirected to arbitrary subject in github.com/nats-io/nats-server
GO-2026-4827: NATS credentials are exposed in monitoring port via command-line argv in github.com/nats-io/nats-server
GO-2026-4828: NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching in github.com/nats-io/nats-server
GO-2026-4829: NATS Server panic via malicious compression on leafnode port in github.com/nats-io/nats-server
GO-2026-4830: NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers in github.com/nats-io/nats-server
GO-2026-4831: NATS is vulnerable to pre-auth DoS through WebSockets client service in github.com/nats-io/nats-server
GO-2026-4832: NATS JetStream has an authorization bypass through its Management API in github.com/nats-io/nats-server
GO-2026-4833: NATS is vulnerable to MQTT hijacking via Client ID in github.com/nats-io/nats-server
GO-2026-4834: NATS allows MQTT clients to bypass ACL checks in github.com/nats-io/nats-server
GO-2026-4835: NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing in github.com/nats-io/nats-server
GO-2026-4836: NATS has MQTT plaintext password disclosure in github.com/nats-io/nats-server
GO-2026-4837: NATS has pre-auth server panic via leafnode handling in github.com/nats-io/nats-server
GO-2026-4841: NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead in github.com/nats-io/nats-server

The highest tagged major version is
v2.
package
Version:
v1.4.1
Opens a new window with list of versions in this module.
Published: Feb 7, 2019
License: Apache-2.0
Opens a new window with license information.
Imports: 7
Opens a new window with list of imports.
Imported by: 1
Opens a new window with list of known importers.
Documentation
¶
Source Files
¶
Click to show internal directories.
Click to hide internal directories.