CVE-2026-33248
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33248 is an authentication bypass vulnerability in NATS-Server affecting the verify_and_map mTLS client identity mechanism. When deriving a NATS identity from a TLS client certificate's Subject Distinguished Name (DN), certain Relative Distinguished Name (RDN) patterns are not correctly enforced, enabling authentication bypass. The vulnerability affects NATS-Server versions prior to 2.11.15 and versions 2.12.0 through 2.12.5. It was published on March 24, 2026, with fixes released the same day. The CVSS v3.1 base score is 4.2 (Medium) (GitHub Advisory, NATS Security Advisory).

Technical details

The root cause is improper authentication logic (CWE-287) combined with improper certificate validation (CWE-295) and authentication bypass by alternate name (CWE-289). Specifically, when the verify_and_map configuration option is used, the server derives a NATS client identity from the Subject DN of the presented TLS client certificate. Certain RDN construction patterns within the Subject DN are not correctly matched or enforced by the server's parsing logic, allowing a client presenting a certificate with a crafted DN to bypass identity checks and assume an unintended NATS identity. Exploitation requires the attacker to possess a valid certificate issued by a CA already trusted for client authentication — the attack is not possible with self-signed or untrusted certificates (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows an attacker with a valid certificate from a trusted CA to bypass NATS client authentication and assume an unintended NATS identity. This results in limited confidentiality and integrity impact — the attacker may be able to subscribe to or publish messages on subjects they are not authorized to access, potentially exposing sensitive messaging data or injecting unauthorized messages into the system. Availability is not impacted. The scope is limited to the NATS messaging infrastructure, but depending on the sensitivity of data flowing through the system, unauthorized access to messaging subjects could facilitate lateral movement or data exfiltration within cloud or edge environments (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-33248. The EPSS score is approximately 0.009% (1st percentile), indicating a very low probability of exploitation in the near term (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NATS maintainers themselves characterize this as an unlikely attack, as it requires both a valid certificate from a trusted CA and highly specific, sophisticated DN naming patterns that are considered rare in practice (NATS Security Advisory). No threat actor attribution has been reported.

Exploitation steps

  1. Prerequisite — Obtain a valid certificate: Acquire a TLS client certificate issued by a Certificate Authority (CA) that is already trusted by the target NATS-Server for client authentication. This could be a legitimately issued certificate or one obtained through compromise of the CA.
  2. Identify target configuration: Confirm the target NATS-Server is configured with verify_and_map enabled, which maps client identity from the TLS certificate's Subject DN. Servers not using this configuration are not affected.
  3. Craft a certificate with a specific DN pattern: Construct or request a certificate whose Subject DN uses RDN patterns that exploit the incorrect matching logic — specifically patterns that the server's DN enforcement does not correctly validate, allowing the presented identity to be mapped to a different, higher-privileged NATS identity.
  4. Connect to the NATS-Server: Initiate a TLS connection to the NATS-Server using the crafted certificate. The server's flawed DN matching logic maps the client to an unintended NATS identity.
  5. Access unauthorized subjects: Once authenticated under the bypassed identity, publish or subscribe to NATS subjects that the attacker's legitimate identity would not normally be permitted to access (GitHub Advisory, NATS Security Advisory).

Indicators of compromise

  • Logs: NATS-Server authentication logs showing client connections where the resolved NATS identity does not match the expected mapping for the presented certificate's Subject DN; unexpected identity assignments in server audit logs.
  • Network: TLS client connections from unexpected or unusual certificate Subject DNs, particularly those with complex or multi-valued RDN patterns not consistent with your organization's CA issuance practices.
  • Configuration Review: Presence of verify_and_map in NATS-Server configuration combined with server versions prior to 2.11.15 or between 2.12.0 and 2.12.5 indicates potential exposure (GitHub Advisory).

Mitigation and workarounds

Upgrade NATS-Server to version 2.11.15 or 2.12.6, which contain the fix for this vulnerability (GitHub Advisory, NATS Security Advisory). As a workaround for environments that cannot immediately upgrade, administrators should review and tighten CA certificate issuance practices to ensure that certificates with unusual or complex RDN patterns cannot be issued to unauthorized parties. Organizations not using the verify_and_map mTLS configuration are not affected and do not need to take action.

Community reactions

The vulnerability was published by NATS maintainer philpennock via the GitHub Security Advisory on March 24, 2026, with the maintainers themselves noting it is an "unlikely attack" due to the specific preconditions required (GitHub Advisory). Red Hat tracked the issue via Bugzilla and OpenSUSE issued a security announcement referencing the vulnerability (Red Hat Bugzilla). Community reaction has been muted, consistent with the low EPSS score and the maintainers' own assessment of limited real-world risk.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

nats-server

Affected

sid

nats-server: 2.12.6-1

Fixed

trixie

nats-server

Affected

Ubuntu

Unknown

devel

nats-server

Unknown

noble

nats-server

Unknown

noble (esm-apps)

nats-server

Unknown

resolute

nats-server

Unknown

resolute (esm-apps)

nats-server

Unknown

RHEL / CentOS

Affected

OpenShift

openshift4/oc-mirror-plugin-rhel9

Affected

Alpine

Fixed

edge

nats-server: 2.12.6-r0

Fixed

v3.23

nats-server: 2.12.6-r0

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management