PT-2026-27621 · Nats.Io · Nats Server

Publicado

2026-03-24

·

Atualizado

2026-05-21

·

CVE-2026-33248

CVSS v3.1

4.2

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NATS-Server versions prior to 2.11.15 NATS-Server versions prior to 2.12.6
Description NATS-Server, a high-performance server for NATS.io, a cloud and edge native messaging system, has an issue where, when using mTLS for client identity with verify and map to derive a NATS identity from the client certificate's Subject DN, certain patterns of Relative Distinguished Name (RDN) are not correctly enforced, potentially allowing for authentication bypass. This requires a valid certificate from a trusted Certificate Authority (CA) and specific DN naming patterns. The maintainers consider exploitation unlikely, but sophisticated administrators with specific DN construction patterns might be impacted.
Recommendations Update NATS-Server to version 2.11.15 or later. Update NATS-Server to version 2.12.6 or later. Review CA issuing practices.

Exploit

Correção

Improper Authentication

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-NATS-2026-33248
CVE-2026-33248
GHSA-3F24-PCVM-5JQC
GO-2026-4828
SUSE-SU-2026:1135-1

Produtos afetados

Nats Server