PT-2026-27618 · Nats.Io · Nats Server

CVE-2026-33223

·

Publicado

2026-03-24

·

Atualizado

2026-07-30

CVSS v3.1

6.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NATS-Server versions prior to 2.11.15 NATS-Server versions prior to 2.12.6
Description NATS-Server, a high-performance server for NATS.io, a cloud and edge native messaging system, contains an issue where the Nats-Request-Info: message header does not effectively guarantee identity. The stripping of this header from inbound messages was not fully effective, allowing an attacker with valid credentials to spoof their identity to services that rely on this header. The Nats-Request-Info: header is intended to provide information about a request.
Recommendations Update to NATS-Server version 2.11.15 or later. Update to NATS-Server version 2.12.6 or later.

Exploit

Correção

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-NATS-2026-33223
CVE-2026-33223
GHSA-PWX7-FX9R-HR4H
GO-2026-4835
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Produtos afetados

Nats Server