CLEANSTART-2026-CP20786

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-CP20786.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-CP20786
Upstream
  • CVE-2026-27145
  • CVE-2026-33811
  • CVE-2026-33814
  • CVE-2026-39817
  • CVE-2026-39819
  • CVE-2026-39820
  • CVE-2026-39823
  • CVE-2026-39824
  • CVE-2026-39825
  • CVE-2026-39826
  • CVE-2026-39827
  • CVE-2026-39828
  • CVE-2026-39829
  • CVE-2026-39830
  • CVE-2026-39831
  • CVE-2026-39832
  • CVE-2026-39833
  • CVE-2026-39834
  • CVE-2026-39835
  • CVE-2026-39836
  • CVE-2026-42499
  • CVE-2026-42501
  • CVE-2026-42504
  • CVE-2026-42507
  • CVE-2026-42508
  • CVE-2026-46595
  • CVE-2026-46597
  • CVE-2026-46598
Published
2026-06-10T01:14:55.975405Z
Modified
2026-06-22T09:45:13.493983736Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU
Details

Multiple security vulnerabilities affect the nats-streaming package. Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. See references for individual vulnerability details.

References

Affected packages

CleanStart / nats-streaming

Package

Name
nats-streaming

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.24.6-r1

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-CP20786.json"