NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-26149.json"