The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.
Start learningUpgrade github.com/nats-io/nats-server/v2/server to version 2.12.12, 2.14.3 or higher.
github.com/nats-io/nats-server/v2/server is an A simple, secure and performant communications system for digital systems, services and devices.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the MQTT CONNECT packet parser, which retains incomplete CONNECT packets before authentication completes while awaiting the full advertised packet length. An attacker can exhaust server memory and cause denial of service by opening MQTT connections and sending large partial CONNECT packets that the server buffers pending the rest of the packet. Exploitation affects only deployments with MQTT enabled, and the buffered memory is released once the authentication timeout disconnects the client.