CVE-2026-33223
MEDIUMNATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
Title source: cnaDescription
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from inbound messages was not fully effective. An attacker with valid credentials for any regular client interface could thus spoof their identity to services which rely upon this header. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/nats-io/nats-server/security/advisories/GHSA-pwx7-fx9r-hr4h
X_Refsource_Misc x_refsource_misc
https://advisories.nats.io/CVE/secnote-2026-09.txt
Scores
CVSS v3
6.4
EPSS
0.0021
EPSS Percentile
11.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-290
Status
published
Products (5)
linuxfoundation/nats-server
< 2.11.15
nats-io/nats-server
0Go
nats-io/nats-server
0 - 2.11.15Go
nats-io/nats-server
< 2.11.15
nats-io/nats-server
>= 2.12.0-RC.1, < 2.12.6
Published
Mar 25, 2026
Tracked Since
Mar 26, 2026