PT-2026-27617 · Nats.Io · Nats Server
CVE-2026-33222
·
Publicado
2026-03-24
·
Atualizado
2026-06-18
CVSS v3.1
4.9
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NATS-Server versions prior to 2.11.15
NATS-Server versions prior to 2.12.6
Description
NATS-Server, a high-performance server for NATS.io, contains an issue where users with JetStream admin API access to restore one stream could restore to other stream names. This could impact data that should have been protected from unauthorized access. The JetStream management API, which includes backup and restore functionality, is affected.
Recommendations
Update to version 2.11.15 or later.
Update to version 2.12.6 or later.
If limited JetStream restore permissions are configured for users, temporarily remove those permissions.
Exploit
Correção
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nats Server