Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81642.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-81642
Upstream
Published
2026-03-25T20:16:30Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-29785 affecting package telegraf for versions less than 1.31.0-19
Details

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.

References

Affected packages

Azure Linux:3 / telegraf

Package

Name
telegraf
Purl
pkg:rpm/azure-linux/telegraf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.31.0-19

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81642.json"