PT-2026-27618 · Nats.Io · Nats Server

CVE-2026-33223

·

Published

2026-03-24

·

Updated

2026-07-30

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NATS-Server versions prior to 2.11.15 NATS-Server versions prior to 2.12.6
Description NATS-Server, a high-performance server for NATS.io, a cloud and edge native messaging system, contains an issue where the Nats-Request-Info: message header does not effectively guarantee identity. The stripping of this header from inbound messages was not fully effective, allowing an attacker with valid credentials to spoof their identity to services that rely on this header. The Nats-Request-Info: header is intended to provide information about a request.
Recommendations Update to NATS-Server version 2.11.15 or later. Update to NATS-Server version 2.12.6 or later.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NATS-2026-33223
CVE-2026-33223
GHSA-PWX7-FX9R-HR4H
GO-2026-4835
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Affected Products

Nats Server