PT-2026-27613 · Nats.Io · Nats Server
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NATS-Server versions prior to 2.11.15
NATS-Server versions prior to 2.12.6
Description
NATS-Server, a high-performance server for NATS.io, a cloud and edge native messaging system, contains an issue where MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints in MQTT deployments using usercodes and passwords. As a result, sensitive password information may be accessible through these endpoints. It is recommended to adequately secure monitoring endpoints and avoid exposing them to untrusted networks.
Recommendations
Update NATS-Server to version 2.11.15 or later.
Update NATS-Server to version 2.12.6 or later.
Ensure monitoring endpoints are adequately secured.
Avoid exposing the monitoring endpoint to the Internet or other untrusted network users.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nats Server