
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33246 is an authentication bypass by spoofing vulnerability in NATS-Server, a high-performance messaging server for the NATS.io cloud and edge native messaging system. The flaw allows a leafnode connection to spoof the Nats-Request-Info: message header, enabling identity impersonation of NATS clients that rely on this header for account/user identification. Affected versions include all nats-server releases before 2.11.15 and versions 2.12.0 through 2.12.5. The vulnerability was published on March 24, 2026, with fixes released the same day. It carries a CVSS v3.1 base score of 6.4 (Moderate) per the GitHub Security Advisory, or 5.4 (Medium) per NVD scoring (GitHub Advisory, Red Hat Bugzilla).
The root cause is improper authentication (CWE-287) and authentication bypass by spoofing (CWE-290) arising from insufficient trust validation of leafnode connections in NATS-Server. In hub/spoke topologies, a leafnode server connecting to a hub nats-server is not fully trusted unless the system account is also bridged; however, prior to the fix, identity claims embedded in the Nats-Request-Info: header were propagated without adequate verification. An attacker controlling a leafnode can craft messages with forged Nats-Request-Info: headers, causing downstream NATS clients that trust this header for access control decisions to act on false identity information. The attack requires network access and low-level privileges (e.g., the ability to establish a leafnode connection), but no user interaction (GitHub Advisory, NATS Security Advisory).
Successful exploitation allows an attacker to spoof the account and user identity presented to NATS clients via the Nats-Request-Info: header, potentially causing those clients to grant unauthorized access or make incorrect trust decisions. The vulnerability does not directly compromise the nats-server itself, but any NATS client application that uses this header for authorization logic is at risk of confidentiality and integrity breaches — for example, accessing data or performing actions intended only for a different user or account. The CVSS scoring reflects a scope change, meaning the impact extends beyond the nats-server component to the broader ecosystem of dependent client applications (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.034% (11th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to have the ability to establish a leafnode connection to the target nats-server, which limits the attack surface to environments with exposed or misconfigured leafnode endpoints (GitHub Advisory).
Nats-Request-Info: header containing the account and user identity of a legitimate, higher-privileged NATS user or account.Nats-Request-Info: header for identity-based access control.Nats-Request-Info: headers are being published.Upgrade nats-server to version 2.11.15 or 2.12.6, which contain the fix for this vulnerability. There are no known configuration-based workarounds available. As an interim measure, operators should restrict leafnode connectivity to only fully trusted servers and ensure the system account is bridged for any leafnode that requires identity propagation. NATS client developers should avoid relying solely on the Nats-Request-Info: header for security-critical access control decisions until the server is patched (GitHub Advisory, NATS Security Advisory).
The advisory was published by NATS maintainer philpennock on March 24, 2026, and was promptly indexed by Red Hat's security response team and INCIBE-CERT. OpenSUSE also issued a security announcement referencing this CVE. No significant public researcher commentary or social media discussion has been identified beyond standard vulnerability tracking and distribution channels (GitHub Advisory, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
devel
nats-server
noble
nats-server
noble (esm-apps)
nats-server
resolute
nats-server
resolute (esm-apps)
nats-server
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."