CVE-2026-33246General(linuxfoundation / nats-server)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message header, providing information about a request. This is supposed to provide enough information to allow for account/user identification, such that NATS clients could make their own decisions on how to trust a message, provided that they trust the nats-server as a broker. A leafnode connecting to a nats-server is not fully trusted unless the system account is bridged too. Thus identity claims should not have propagated unchecked. Prior to versions 2.11.15 and 2.12.6, NATS clients relying upon the Nats-Request-Info: header could be spoofed. This does not directly affect the nats-server itself, but the CVSS Confidentiality and Integrity scores are based upon what a hypothetical client might choose to do with this NATS header. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nats-server

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
nats-server

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-25: 103-25
Signal classification1 categories
General
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • CVE@CVEnew
    General

    CVE-2026-33246 NATS-Server is a High-Performance server for http://NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message header, providin… https://www.cve.org/CVERecord?id=CVE-2026-33246

    Post summary

    The post references CVE‑2026‑33246 for NATS‑Server but provides no proof‑of‑concept, exploit code, or mitigation details, nor any discussion of active exploitation or false positives.

    00001112
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationnats-server---

Explore more