{"id":"AZL-81642","summary":"CVE-2026-29785 affecting package telegraf for versions less than 1.31.0-19","details":"NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the \"leafnode\" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.","modified":"2026-08-30T05:26:50Z","published":"2026-03-25T20:16:30Z","upstream":["CVE-2026-29785"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29785"}],"affected":[{"package":{"name":"telegraf","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/telegraf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.31.0-19"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81642.json"}}],"schema_version":"1.9.0"}