PT-2026-27618 · Nats.Io · Nats Server
CVE-2026-33223
·
Published
2026-03-24
·
Updated
2026-07-30
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NATS-Server versions prior to 2.11.15
NATS-Server versions prior to 2.12.6
Description
NATS-Server, a high-performance server for NATS.io, a cloud and edge native messaging system, contains an issue where the
Nats-Request-Info: message header does not effectively guarantee identity. The stripping of this header from inbound messages was not fully effective, allowing an attacker with valid credentials to spoof their identity to services that rely on this header. The Nats-Request-Info: header is intended to provide information about a request.Recommendations
Update to NATS-Server version 2.11.15 or later.
Update to NATS-Server version 2.12.6 or later.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nats Server