CVE-2026-33223
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33223 is an identity spoofing vulnerability in NATS-Server, a high-performance messaging server for NATS.io, caused by incomplete stripping of the Nats-Request-Info: message header from inbound client messages. The vulnerability affects all versions of github.com/nats-io/nats-server/v2 prior to 2.11.15 and versions 2.12.0-RC.1 through 2.12.5. It was published on March 24, 2026, by maintainer philpennock via GitHub Security Advisory GHSA-pwx7-fx9r-hr4h, and assigned a CVE by NVD on March 25, 2026. The CVSS v3.1 base score is 6.4 (Moderate) per the GitHub Advisory, though Feedly's data reflects a score of 5.4 (Medium) under a slightly different vector (GitHub Advisory, NATS Advisory).

Technical details

The root cause is classified under CWE-290 (Authentication Bypass by Spoofing) and CWE-807 (Reliance on Untrusted Inputs in a Security Decision). The Nats-Request-Info: header is intended to be injected exclusively by the NATS server to convey trusted identity information about a request; however, the server's logic for stripping this header from messages arriving on regular client interfaces was incomplete, allowing a client to inject a crafted Nats-Request-Info: header that persists into the message delivery pipeline. An attacker with valid credentials for any standard NATS client connection can craft messages containing a spoofed header value, causing downstream services that rely on this header for identity verification to act on falsified identity data (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows an authenticated attacker to impersonate other identities to backend services that trust the Nats-Request-Info: header for access control or authorization decisions, resulting in low confidentiality and low integrity impacts with no availability impact. The scope is marked as "Changed" in the GitHub advisory's CVSS vector, indicating that the impact extends beyond the vulnerable NATS server component itself to dependent services in the messaging ecosystem. This could enable unauthorized access to data or actions within services that rely on NATS-based identity guarantees, particularly in microservice architectures where NATS is used as a trusted messaging backbone (GitHub Advisory, NATS Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.012% (2nd percentile), indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability requires valid NATS client credentials, which limits the attacker pool to those with at least low-privilege access to the messaging system. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Obtain valid credentials: Acquire any valid NATS client credentials (username/password, token, or NKey) for the target NATS server — these can be low-privilege credentials for any regular client interface.
  2. Connect to the NATS server: Establish a standard NATS client connection to the target server using a NATS client library (e.g., nats.go, nats.py).
  3. Craft a spoofed message: Construct a NATS message that includes a manually injected Nats-Request-Info: header containing the identity of a different, higher-privileged client or service account you wish to impersonate.
  4. Publish the message: Publish the crafted message to a subject monitored by a backend service that uses the Nats-Request-Info: header to make authorization or identity-based decisions.
  5. Achieve identity spoofing: Because the server fails to fully strip the attacker-supplied header, the downstream service receives the message with the forged identity header and processes the request as if it originated from the spoofed identity, potentially granting unauthorized access or actions (GitHub Advisory, NATS Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous NATS client connections from unusual source IPs or accounts publishing to subjects they would not normally access.
  • Logs: NATS server logs showing messages published by a client that contain Nats-Request-Info: headers not injected by the server itself; audit logs of downstream services recording actions attributed to identities inconsistent with the actual connecting client.
  • Behavioral: Backend services performing actions or granting access to resources associated with a different identity than the authenticated NATS client; authorization decisions in dependent microservices that do not align with the connecting client's actual permission level.

Mitigation and workarounds

Upgrade NATS-Server to version 2.11.15 or 2.12.6, which contain the fix for this vulnerability. There are no known configuration-based workarounds available. Organizations using NATS in environments where the Nats-Request-Info: header is relied upon for identity or authorization decisions should treat this upgrade as a priority (GitHub Advisory, NATS Advisory). OpenSUSE users can also refer to the distribution-level security announcement for package updates (OpenSUSE Security).

Community reactions

The vulnerability was published by NATS maintainer philpennock and received standard coverage across vulnerability tracking platforms including Red Hat Bugzilla, VulnDB, and GitLab Advisories. Red Hat has tracked the issue as medium severity and OpenSUSE issued a security announcement for its packaged version of nats-server (Red Hat Bugzilla, OpenSUSE Security). No notable independent researcher commentary or significant social media discussion beyond automated CVE tracking posts has been identified.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

nats-server

Affected

sid

nats-server: 2.12.6-1

Fixed

trixie

nats-server

Affected

Ubuntu

Unknown

devel

nats-server

Unknown

noble

nats-server

Unknown

noble (esm-apps)

nats-server

Unknown

resolute

nats-server

Unknown

resolute (esm-apps)

nats-server

Unknown

RHEL / CentOS

Affected

OpenShift

openshift4/oc-mirror-plugin-rhel9

Affected

Alpine

Fixed

edge

nats-server: 2.12.6-r0

Fixed

v3.23

nats-server: 2.12.6-r0

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management