CVE-2026-33223Authentication Bypass by Spoofing in Nats-server

Severity
5.4MEDIUMNVD
EPSS
0.0%
top 92.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMar 26

Description

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from inbound messages was not fully effective. An attacker with valid credentials for any regular client interface could thus spoof their identity to services which rely upon this header. Versions 2.11.15 and 2.12.6 contain a

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages5 packages

debiandebian/nats-server< nats-server 2.12.6-1 (forky)
CVEListV5nats-io/nats-server< 2.11.15+1
NVDlinuxfoundation/nats-server2.12.02.12.6+1
Gogithub.com/nats-io_nats-server_v22.12.0-RC.12.12.6+1
Debianlinuxfoundation/nats-server< 2.12.6-1

🔴Vulnerability Details

4
OSV
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing in github.com/nats-io/nats-server2026-03-26
OSV
CVE-2026-33223: NATS-Server is a High-Performance server for NATS2026-03-25
OSV
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing2026-03-24
GHSA
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing2026-03-24

📋Vendor Advisories

2
Red Hat
nats-server: github.com/nats-io/nats-server: NATS-Server: Identity spoofing via `Nats-Request-Info:` header2026-03-25
Debian
CVE-2026-33223: nats-server - NATS-Server is a High-Performance server for NATS.io, a cloud and edge native me...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-33223 Impact, Exploitability, and Mitigation Steps | Wiz