CVE-2026-33249
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33249 is an incorrect authorization vulnerability in NATS-Server (nats-io/nats-server) that allows an authenticated client to redirect message tracing output to arbitrary subjects without the required publish permissions. The vulnerability was published on March 24, 2026, and affects NATS-Server versions 2.11.0 through 2.11.14 and 2.12.0-preview.1 through 2.12.5. Fixed versions 2.11.15 and 2.12.6 were released simultaneously with disclosure. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization) and CWE-1220 (Insufficient Granularity of Access Control). NATS-Server supports per-message telemetry via NATS message tracing headers; a valid, authenticated client can set a tracing header that instructs the server to deliver trace messages to an arbitrary subject — including subjects for which the client lacks publish permission. Critically, the payload delivered to the unauthorized subject is a valid, server-generated trace message and is not attacker-controlled content. Exploitation requires only low-privilege network access and no user interaction (GitHub Advisory, NATS Advisory).

Impact

Successful exploitation allows a low-privileged authenticated attacker to route trace messages to subjects they are not authorized to publish to, violating the server's access control model. The integrity impact is limited — the attacker cannot control the content of the trace message payload, only its destination subject. There is no confidentiality or availability impact, and the scope is unchanged, meaning the vulnerability does not enable lateral movement or data exfiltration beyond unauthorized message routing within the NATS messaging fabric (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). No threat actor attribution has been reported. The EPSS score is approximately 0.026% (2nd percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Nessus (ID 303845) and Qualys (IDs 761875, 6563643) (Feedly).

Exploitation steps

  1. Authenticate to NATS-Server: Obtain valid credentials for a low-privileged NATS client account on a server running versions 2.11.0–2.11.14 or 2.12.0-preview.1–2.12.5.
  2. Identify target subject: Determine an arbitrary valid subject on the NATS server to which the attacker does not have publish permission but wishes to deliver messages.
  3. Craft a message with tracing header: Construct a NATS message that includes the message tracing header (e.g., Nats-Trace-Dest) set to the target unauthorized subject.
  4. Publish the message: Send the crafted message through the NATS client. The server processes the tracing header without verifying the client's publish permission for the specified trace destination subject.
  5. Trace message delivered: The server routes a valid trace message to the unauthorized subject, bypassing the publish ACL for that subject (GitHub Advisory, NATS Advisory).

Indicators of compromise

  • Network: Unexpected NATS publish activity to subjects that a given client account is not authorized to publish to, observable via NATS server monitoring endpoints (e.g., /connz, /subsz).
  • Logs: NATS-Server logs showing trace message delivery to subjects inconsistent with the publishing client's configured permissions; audit log entries where a client's trace destination differs from its authorized publish subjects.
  • Behavioral: Unusual message tracing header (Nats-Trace-Dest) values in client connections pointing to sensitive or administrative subjects; clients sending messages with tracing headers to subjects outside their normal operational scope.

Mitigation and workarounds

Upgrade NATS-Server to version 2.11.15 or 2.12.6, which contain the fix for this vulnerability (GitHub Advisory, NATS Advisory). The vendor has confirmed there are no known workarounds available. As a defense-in-depth measure, restrict publish permissions carefully to limit which subjects authenticated users can access, and monitor message tracing activity for suspicious redirection patterns to unauthorized subjects (Red Hat Bugzilla).

Community reactions

The advisory was published by philpennock on the nats-io/nats-server GitHub repository on March 24, 2026, and was simultaneously cross-referenced with the canonical NATS security advisory at advisories.nats.io. Red Hat tracked the issue via Bugzilla (Bug 2451485) and classified it as medium severity. openSUSE issued a security announcement referencing the vulnerability, and it was picked up by Linux security aggregators shortly after disclosure (openSUSE, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management