depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access
depscope/go/github.com/nats-io/nats-server

github.com/nats-io/nats-server

govv1.4.1

High-Performance server for NATS.io, the cloud and edge native messaging system.

License Apache-2.0permissive25 versions216 maintainers0 deps19,695 weekly dl
nats-io/nats-server
27
/ 100
Health
update required

github.com/nats-io/[email protected] has vulnerabilities — update to latest

Update to >= 2.2.3 to fix known vulnerabilities

  • Low health score (27/100)
  • 5 high severity vulnerabilities
Health breakdown0 – 100
0/25
maintenance
10/20
popularity
0/25
security
12/15
maturity
5/15
community
Vulnerabilities
15
5 high6 medium4 low
Advisories (15)
SeverityIDSummaryFixed in
mediumBIT-nats-2026-33248NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching2.12.6
highBIT-nats-2026-29785NATS Server panic via malicious compression on leafnode port2.12.5
mediumBIT-nats-2026-33246NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers2.12.6
mediumBIT-nats-2026-33219NATS is vulnerable to pre-auth DoS through WebSockets client service2.12.6
mediumBIT-nats-2026-33222NATS JetStream has an authorization bypass through its Management API2.12.6
highBIT-nats-2026-33217NATS allows MQTT clients to bypass ACL checks2.12.6
highBIT-nats-2020-28466Denial of service in github.com/nats-io/nats-server/server2.2.0
mediumBIT-nats-2026-33223NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing2.12.6
mediumBIT-nats-2026-27571nats-server websockets are vulnerable to pre-auth memory DoS2.12.3
highBIT-nats-2026-33216NATS has MQTT plaintext password disclosure2.12.6
highBIT-nats-2026-33218NATS has pre-auth server panic via leafnode handling2.12.6
unknownGHSA-gwj5-3vfq-q992Import loops in account imports, nats-server DoS in github.com/nats-io/nats-server2.2.0
unknownCVE-2019-13126Integer Overflow or Wraparound in NATS Server in github.com/nats-io/nats-server2.2.0
unknownBIT-nats-2020-28466Denial of service in github.com/nats-io/nats-server/server in github.com/nats-io/nats-server2.2.0
unknownCVE-2021-32026NATS server TLS missing ciphersuite settings when CLI flags used in github.com/nats-io/nats-server2.2.3

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/nats-io/nats-server

Last updated · 2019-02-07T23:30:30Z

DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents