
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33223 is an identity spoofing vulnerability in NATS-Server, a high-performance messaging server for NATS.io, caused by incomplete stripping of the Nats-Request-Info: message header from inbound client messages. The vulnerability affects all versions of github.com/nats-io/nats-server/v2 prior to 2.11.15 and versions 2.12.0-RC.1 through 2.12.5. It was published on March 24, 2026, by maintainer philpennock via GitHub Security Advisory GHSA-pwx7-fx9r-hr4h, and assigned a CVE by NVD on March 25, 2026. The CVSS v3.1 base score is 6.4 (Moderate) per the GitHub Advisory, though Feedly's data reflects a score of 5.4 (Medium) under a slightly different vector (GitHub Advisory, NATS Advisory).
The root cause is classified under CWE-290 (Authentication Bypass by Spoofing) and CWE-807 (Reliance on Untrusted Inputs in a Security Decision). The Nats-Request-Info: header is intended to be injected exclusively by the NATS server to convey trusted identity information about a request; however, the server's logic for stripping this header from messages arriving on regular client interfaces was incomplete, allowing a client to inject a crafted Nats-Request-Info: header that persists into the message delivery pipeline. An attacker with valid credentials for any standard NATS client connection can craft messages containing a spoofed header value, causing downstream services that rely on this header for identity verification to act on falsified identity data (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows an authenticated attacker to impersonate other identities to backend services that trust the Nats-Request-Info: header for access control or authorization decisions, resulting in low confidentiality and low integrity impacts with no availability impact. The scope is marked as "Changed" in the GitHub advisory's CVSS vector, indicating that the impact extends beyond the vulnerable NATS server component itself to dependent services in the messaging ecosystem. This could enable unauthorized access to data or actions within services that rely on NATS-based identity guarantees, particularly in microservice architectures where NATS is used as a trusted messaging backbone (GitHub Advisory, NATS Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.012% (2nd percentile), indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability requires valid NATS client credentials, which limits the attacker pool to those with at least low-privilege access to the messaging system. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
nats.go, nats.py).Nats-Request-Info: header containing the identity of a different, higher-privileged client or service account you wish to impersonate.Nats-Request-Info: header to make authorization or identity-based decisions.Nats-Request-Info: headers not injected by the server itself; audit logs of downstream services recording actions attributed to identities inconsistent with the actual connecting client.Upgrade NATS-Server to version 2.11.15 or 2.12.6, which contain the fix for this vulnerability. There are no known configuration-based workarounds available. Organizations using NATS in environments where the Nats-Request-Info: header is relied upon for identity or authorization decisions should treat this upgrade as a priority (GitHub Advisory, NATS Advisory). OpenSUSE users can also refer to the distribution-level security announcement for package updates (OpenSUSE Security).
The vulnerability was published by NATS maintainer philpennock and received standard coverage across vulnerability tracking platforms including Red Hat Bugzilla, VulnDB, and GitLab Advisories. Red Hat has tracked the issue as medium severity and OpenSUSE issued a security announcement for its packaged version of nats-server (Red Hat Bugzilla, OpenSUSE Security). No notable independent researcher commentary or significant social media discussion beyond automated CVE tracking posts has been identified.
Fix availability across major Linux distributions and their releases.
devel
nats-server
noble
nats-server
noble (esm-apps)
nats-server
resolute
nats-server
resolute (esm-apps)
nats-server
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."