PT-2026-27618 · Nats.Io · Nats Server
CVE-2026-33223
·
Publicado
2026-03-24
·
Atualizado
2026-07-30
CVSS v3.1
6.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NATS-Server versions prior to 2.11.15
NATS-Server versions prior to 2.12.6
Description
NATS-Server, a high-performance server for NATS.io, a cloud and edge native messaging system, contains an issue where the
Nats-Request-Info: message header does not effectively guarantee identity. The stripping of this header from inbound messages was not fully effective, allowing an attacker with valid credentials to spoof their identity to services that rely on this header. The Nats-Request-Info: header is intended to provide information about a request.Recommendations
Update to NATS-Server version 2.11.15 or later.
Update to NATS-Server version 2.12.6 or later.
Exploit
Correção
Authentication Bypass by Spoofing
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nats Server