CVE-2026-33223 Details
Description
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from inbound messages was not fully effective. An attacker with valid credentials for any regular client interface could thus spoof their identity to services which rely upon this header. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.
A vulnerability exists in NATS-Server versions prior to 2.11.15 and 2.12.6, allowing identity spoofing through the Nats-Request-Info header. This header is intended to guarantee identity, but the removal of the header from incoming messages was not completely effective. As a result, an attacker with valid credentials for any regular client interface could impersonate their identity to services that depend on this header.
Users can upgrade to NATS-Server versions 2.12.6 or 2.11.15 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisories.nats.io/CVE/secnote-2026-09.txt | [email protected] | Vendor Advisory |
| https://github.com/nats-io/nats-server/security/advisories/GHSA-pwx7-fx9r-hr4h | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation nats-server | < 2.11.15 >= 2.12.0, < 2.12.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Mar 25, 2026 | New CVE Received | [email protected] |