Vulnerability

CVE-2020-26521
CVSS Score 7.5 high

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CWE

CWE-476

[CVE-2020-26521] CWE-476: NULL Pointer Dereference

Description

The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).

See github.com/nats-io/nats-server/v2 package information