
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33248 is an authentication bypass vulnerability in NATS-Server affecting the verify_and_map mTLS client identity mechanism. When deriving a NATS identity from a TLS client certificate's Subject Distinguished Name (DN), certain Relative Distinguished Name (RDN) patterns are not correctly enforced, enabling authentication bypass. The vulnerability affects NATS-Server versions prior to 2.11.15 and versions 2.12.0 through 2.12.5. It was published on March 24, 2026, with fixes released the same day. The CVSS v3.1 base score is 4.2 (Medium) (GitHub Advisory, NATS Security Advisory).
The root cause is improper authentication logic (CWE-287) combined with improper certificate validation (CWE-295) and authentication bypass by alternate name (CWE-289). Specifically, when the verify_and_map configuration option is used, the server derives a NATS client identity from the Subject DN of the presented TLS client certificate. Certain RDN construction patterns within the Subject DN are not correctly matched or enforced by the server's parsing logic, allowing a client presenting a certificate with a crafted DN to bypass identity checks and assume an unintended NATS identity. Exploitation requires the attacker to possess a valid certificate issued by a CA already trusted for client authentication — the attack is not possible with self-signed or untrusted certificates (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows an attacker with a valid certificate from a trusted CA to bypass NATS client authentication and assume an unintended NATS identity. This results in limited confidentiality and integrity impact — the attacker may be able to subscribe to or publish messages on subjects they are not authorized to access, potentially exposing sensitive messaging data or injecting unauthorized messages into the system. Availability is not impacted. The scope is limited to the NATS messaging infrastructure, but depending on the sensitivity of data flowing through the system, unauthorized access to messaging subjects could facilitate lateral movement or data exfiltration within cloud or edge environments (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-33248. The EPSS score is approximately 0.009% (1st percentile), indicating a very low probability of exploitation in the near term (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NATS maintainers themselves characterize this as an unlikely attack, as it requires both a valid certificate from a trusted CA and highly specific, sophisticated DN naming patterns that are considered rare in practice (NATS Security Advisory). No threat actor attribution has been reported.
verify_and_map enabled, which maps client identity from the TLS certificate's Subject DN. Servers not using this configuration are not affected.verify_and_map in NATS-Server configuration combined with server versions prior to 2.11.15 or between 2.12.0 and 2.12.5 indicates potential exposure (GitHub Advisory).Upgrade NATS-Server to version 2.11.15 or 2.12.6, which contain the fix for this vulnerability (GitHub Advisory, NATS Security Advisory). As a workaround for environments that cannot immediately upgrade, administrators should review and tighten CA certificate issuance practices to ensure that certificates with unusual or complex RDN patterns cannot be issued to unauthorized parties. Organizations not using the verify_and_map mTLS configuration are not affected and do not need to take action.
The vulnerability was published by NATS maintainer philpennock via the GitHub Security Advisory on March 24, 2026, with the maintainers themselves noting it is an "unlikely attack" due to the specific preconditions required (GitHub Advisory). Red Hat tracked the issue via Bugzilla and OpenSUSE issued a security announcement referencing the vulnerability (Red Hat Bugzilla). Community reaction has been muted, consistent with the low EPSS score and the maintainers' own assessment of limited real-world risk.
Fix availability across major Linux distributions and their releases.
devel
nats-server
noble
nats-server
noble (esm-apps)
nats-server
resolute
nats-server
resolute (esm-apps)
nats-server
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."