CVE-2026-33247 Details
Description
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any user who can see the monitoring port, if that too is enabled. The `/debug/vars` end-point contains an unredacted copy of argv. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, configure credentials inside a configuration file instead of via argv, and do not enable the monitoring port if using secrets in argv. Best practice remains to not expose the monitoring port to the Internet, or to untrusted network sources.
A vulnerability exists in NATS-Server versions prior to 2.11.15 and 2.12.6, where static credentials provided via command-line arguments are exposed to users who can access the monitoring port. The '/debug/vars' endpoint reveals an unredacted copy of the command-line arguments, including sensitive credentials, if the monitoring port is enabled.
Users can upgrade to NATS-Server versions 2.12.6 or 2.11.15. As a workaround, configure credentials in a configuration file instead of via command-line arguments, and avoid enabling the monitoring port if secrets are included in the arguments. It is also recommended not to expose the monitoring port to the Internet or untrusted networks.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:21769 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:22347 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:23345 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-33247 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2451486 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33247.json | redhat-SADP | |
| https://advisories.nats.io/CVE/secnote-2026-14.txt | [email protected] | MitigationVendor Advisory |
| https://github.com/nats-io/nats-server/security/advisories/GHSA-x6g4-f6q3-fqvv | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-214 | Invocation of Process Using Visible Sensitive Information | redhat-SADP |
| CWE-215 | Insertion of Sensitive Information Into Debugging Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation nats-server | < 2.11.15 >= 2.12.0, < 2.12.6 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | [email protected] |
| Aug 24, 2026 | CVE Modified | redhat-SADP |
| Aug 17, 2026 | CVE Modified | redhat-SADP |
| Aug 14, 2026 | CVE Modified | redhat-SADP |
| Aug 10, 2026 | CVE Modified | redhat-SADP |
| Aug 3, 2026 | CVE Modified | redhat-SADP |
| Jul 27, 2026 | CVE Modified | redhat-SADP |
| Jul 20, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Mar 25, 2026 | New CVE Received | [email protected] |