Skip to content

Fix NATS server CVEs (v6.2.1)#4108

Merged
reinkrul merged 2 commits intoV6.2from
backport-nats-cve-v6.2
Mar 25, 2026
Merged

Fix NATS server CVEs (v6.2.1)#4108
reinkrul merged 2 commits intoV6.2from
backport-nats-cve-v6.2

Conversation

@reinkrul
Copy link
Copy Markdown
Member

Backport of #4107 to V6.2.

Fixes CVE-2026-33215, CVE-2026-33216, CVE-2026-33217, CVE-2026-33218, CVE-2026-33219, CVE-2026-33222, CVE-2026-33223, CVE-2026-33246, CVE-2026-33247, CVE-2026-33248, CVE-2026-33249 by updating NATS server from 2.11.12 to 2.11.15.

Includes release notes for v6.2.1.

dependabot bot and others added 2 commits March 25, 2026 06:49
Bumps [github.com/nats-io/nats-server/v2](https://github.com/nats-io/nats-server) from 2.11.12 to 2.11.15.
- [Release notes](https://github.com/nats-io/nats-server/releases)
- [Changelog](https://github.com/nats-io/nats-server/blob/main/RELEASES.md)
- [Commits](nats-io/nats-server@v2.11.12...v2.11.15)

---
updated-dependencies:
- dependency-name: github.com/nats-io/nats-server/v2
  dependency-version: 2.11.15
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@qltysh
Copy link
Copy Markdown

qltysh bot commented Mar 25, 2026

Qlty

Coverage Impact

⬇️ Merging this pull request will decrease total coverage on V6.2 by 0.01%.

🚦 See full report on Qlty Cloud »

🛟 Help
  • Diff Coverage: Coverage for added or modified lines of code (excludes deleted files). Learn more.

  • Total Coverage: Coverage for the whole repository, calculated as the sum of all File Coverage. Learn more.

  • File Coverage: Covered Lines divided by Covered Lines plus Missed Lines. (Excludes non-executable lines including blank lines and comments.)

    • Indirect Changes: Changes to File Coverage for files that were not modified in this PR. Learn more.

@reinkrul reinkrul merged commit 98a1528 into V6.2 Mar 25, 2026
8 checks passed
@reinkrul reinkrul deleted the backport-nats-cve-v6.2 branch March 25, 2026 07:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants