Vulnerability Description
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from inbound messages was not fully effective. An attacker with valid credentials for any regular client interface could thus spoof their identity to services which rely upon this header. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Nats-Server | < 2.11.15 |
Related Weaknesses (CWE)
References
- https://advisories.nats.io/CVE/secnote-2026-09.txtVendor Advisory
- https://github.com/nats-io/nats-server/security/advisories/GHSA-pwx7-fx9r-hr4hVendor Advisory
FAQ
What is CVE-2026-33223?
CVE-2026-33223 is a vulnerability with a CVSS score of 6.4 (MEDIUM). NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a g...
How severe is CVE-2026-33223?
CVE-2026-33223 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33223?
Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Nats-Server.