Nats-Io Nats-Server vulnerabilities
24 known vulnerabilities affecting nats-io/nats-server.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM13
Vulnerabilities
Page 2 of 2
CVE-2026-33222P4MEDIUMCVSS 4.9fixed in 2.11.15v>= 2.12.0-RC.1, < 2.12.62026-03-25
CVE-2026-33222 [MEDIUM] CWE-285 CVE-2026-33222: NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prio
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround
nvd
CVE-2026-33249P4MEDIUMCVSS 4.3fixed in 2.12.8v>= 2.14.0-RC.1, < 2.14.32026-03-25
CVE-2026-33249 [MEDIUM] CWE-863 CVE-2026-33249: NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Star
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11.0 and prior to versions 2.11.15 and 2.12.6, a valid client which uses message tracing headers can indicate that the trace messages can be sent to an arbitrary valid subject, including those to which the client does not have publis
nvd
CVE-2026-33248P4MEDIUMCVSS 4.2fixed in 2.11.15v>= 2.12.0-RC.1, < 2.12.62026-03-25
CVE-2026-33248 [MEDIUM] CWE-287 CVE-2026-33248: NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prio
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypas
nvd
CVE-2026-58209P4MEDIUMCVSS 4.3fixed in 2.12.12v>= 2.14.0-RC.1, < 2.14.32026-07-08
CVE-2026-58209 [MEDIUM] CWE-863 CVE-2026-58209: NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Pr
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not consistently recheck the concrete
nvd
← Previous2 / 2