<Vulnerability name="CVE-2026-58207">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-08T20:15:31</PublicDate>
    <Bugzilla id="2498265" url="https://bugzilla.redhat.com/show_bug.cgi?id=2498265" xml:lang="en:us">
github.com/nats-io/nats-server: NATS Server: Denial of Service via arithmetic overflow in connection monitoring pagination
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-190</CWE>
    <Details xml:lang="en:us" source="Mitre">
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the response window was safely bounded. This issue is fixed in versions 2.14.3 and 2.12.12.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in NATS Server. A client with the ability to send account-scoped connection monitoring requests could crash the server. This is achieved by providing pagination offset and limit values that cause an arithmetic overflow, leading to a Denial of Service (DoS).
    </Details>
    <Statement xml:lang="en:us">
CVE.org and NVD independently assess this issue at different severities than Red Hat because CVE.org uses a Changed scope (S:C) in its CVSS vector, treating the crash as impacting components beyond the NATS Server process itself. Red Hat, consistent with NVDs own scoring, assesses the impact as scoped to the NATS Server process (Scope Unchanged), resulting in a CVSS score of 6.5 and a Moderate impact rating. Only account-scoped connection-monitoring requests can trigger the arithmetic overflow, and no Red Hat product runs an externally-reachable, unauthenticated NATS Server monitoring endpoint by default.
    </Statement>
    <Mitigation xml:lang="en:us">
Upstream mitigation: restrict publish access to system request subjects (e.g. \.REQ.ACCOUNT.*.CONNZ) for untrusted clients, and avoid no-auth NATS deployments where untrusted clients can publish to system monitoring request subjects. Upgrading to nats-server 2.14.3 or 2.12.12 (or later) fully resolves the issue.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:multicluster_globalhub">
        <ProductName>Multicluster Global Hub</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>multicluster-globalhub/multicluster-globalhub-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:5">
        <ProductName>Red Hat Ceph Storage 5</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhceph/snmp-notifier-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:6">
        <ProductName>Red Hat Ceph Storage 6</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhceph/snmp-notifier-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:7">
        <ProductName>Red Hat Ceph Storage 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhceph/snmp-notifier-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:8">
        <ProductName>Red Hat Ceph Storage 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhceph/snmp-notifier-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ceph_storage:9">
        <ProductName>Red Hat Ceph Storage 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhceph/snmp-notifier-rhel10</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>nats-server2.12</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>nats-server2.14</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openshift4/oc-mirror-plugin-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-58207
https://nvd.nist.gov/vuln/detail/CVE-2026-58207
https://github.com/nats-io/nats-server/commit/2ae047139e37a38cb01e259a67909e7a39fa38e9
https://github.com/nats-io/nats-server/commit/894d9411927681d66ce349bf1afe49608dc0c1a3
https://github.com/nats-io/nats-server/releases/tag/v2.12.12
https://github.com/nats-io/nats-server/releases/tag/v2.14.3
https://github.com/nats-io/nats-server/security/advisories/GHSA-q59r-vq66-pxc2
    </References>
</Vulnerability>