CVE-2026-33246
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33246 is an authentication bypass by spoofing vulnerability in NATS-Server, a high-performance messaging server for the NATS.io cloud and edge native messaging system. The flaw allows a leafnode connection to spoof the Nats-Request-Info: message header, enabling identity impersonation of NATS clients that rely on this header for account/user identification. Affected versions include all nats-server releases before 2.11.15 and versions 2.12.0 through 2.12.5. The vulnerability was published on March 24, 2026, with fixes released the same day. It carries a CVSS v3.1 base score of 6.4 (Moderate) per the GitHub Security Advisory, or 5.4 (Medium) per NVD scoring (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper authentication (CWE-287) and authentication bypass by spoofing (CWE-290) arising from insufficient trust validation of leafnode connections in NATS-Server. In hub/spoke topologies, a leafnode server connecting to a hub nats-server is not fully trusted unless the system account is also bridged; however, prior to the fix, identity claims embedded in the Nats-Request-Info: header were propagated without adequate verification. An attacker controlling a leafnode can craft messages with forged Nats-Request-Info: headers, causing downstream NATS clients that trust this header for access control decisions to act on false identity information. The attack requires network access and low-level privileges (e.g., the ability to establish a leafnode connection), but no user interaction (GitHub Advisory, NATS Security Advisory).

Impact

Successful exploitation allows an attacker to spoof the account and user identity presented to NATS clients via the Nats-Request-Info: header, potentially causing those clients to grant unauthorized access or make incorrect trust decisions. The vulnerability does not directly compromise the nats-server itself, but any NATS client application that uses this header for authorization logic is at risk of confidentiality and integrity breaches — for example, accessing data or performing actions intended only for a different user or account. The CVSS scoring reflects a scope change, meaning the impact extends beyond the nats-server component to the broader ecosystem of dependent client applications (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.034% (11th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to have the ability to establish a leafnode connection to the target nats-server, which limits the attack surface to environments with exposed or misconfigured leafnode endpoints (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target NATS-Server deployment running a vulnerable version (before 2.11.15 or between 2.12.0 and 2.12.5) that accepts leafnode connections, using network scanning or service enumeration tools.
  2. Establish leafnode connection: Connect to the target hub nats-server as a leafnode (without bridging the system account), gaining a partially trusted position in the hub/spoke topology.
  3. Craft spoofed header: Construct a NATS message that includes a forged Nats-Request-Info: header containing the account and user identity of a legitimate, higher-privileged NATS user or account.
  4. Publish spoofed message: Publish the crafted message through the leafnode connection to a subject monitored by target NATS clients that rely on the Nats-Request-Info: header for identity-based access control.
  5. Achieve objective: The receiving NATS client, trusting the spoofed header, grants access or performs actions as if the message originated from the impersonated identity, enabling unauthorized data access or privilege escalation within the client application (GitHub Advisory, NATS Security Advisory).

Indicators of compromise

  • Network: Unexpected or unauthorized leafnode connections to the nats-server from unknown or untrusted IP addresses; leafnode connections where the system account is not bridged but messages with Nats-Request-Info: headers are being published.
  • Logs: NATS server logs showing leafnode connection events from unfamiliar sources; client application logs recording access grants or actions attributed to user/account identities inconsistent with the actual connecting client.
  • Application Behavior: NATS client applications performing actions or accessing data outside their expected scope, potentially indicating they acted on a spoofed identity header.

Mitigation and workarounds

Upgrade nats-server to version 2.11.15 or 2.12.6, which contain the fix for this vulnerability. There are no known configuration-based workarounds available. As an interim measure, operators should restrict leafnode connectivity to only fully trusted servers and ensure the system account is bridged for any leafnode that requires identity propagation. NATS client developers should avoid relying solely on the Nats-Request-Info: header for security-critical access control decisions until the server is patched (GitHub Advisory, NATS Security Advisory).

Community reactions

The advisory was published by NATS maintainer philpennock on March 24, 2026, and was promptly indexed by Red Hat's security response team and INCIBE-CERT. OpenSUSE also issued a security announcement referencing this CVE. No significant public researcher commentary or social media discussion has been identified beyond standard vulnerability tracking and distribution channels (GitHub Advisory, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

nats-server

Affected

sid

nats-server: 2.12.6-1

Fixed

trixie

nats-server

Affected

Ubuntu

Unknown

devel

nats-server

Unknown

noble

nats-server

Unknown

noble (esm-apps)

nats-server

Unknown

resolute

nats-server

Unknown

resolute (esm-apps)

nats-server

Unknown

RHEL / CentOS

Affected

OpenShift

openshift4/oc-mirror-plugin-rhel9

Affected

Alpine

Fixed

edge

nats-server: 2.12.6-r0

Fixed

v3.23

nats-server: 2.12.6-r0

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management