CVE-2020-26149: Linuxfoundation Nats.deno
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
Affected products
- Linuxfoundation Nats.deno: before 1.0.0-9 (fixed in 1.0.0-9)
- Linuxfoundation Nats.js: before 2.0.0-209 (fixed in 2.0.0-209)
- Linuxfoundation Nats.ws: before 1.0.0-111 (fixed in 1.0.0-111)
Published 2020-09-30. Last modified 2026-06-17.