A vulnerability categorized as critical has been discovered in nats-io nats-server up to 2.11.14/2.12.5. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to incorrect authorization. This vulnerability is registered as CVE-2026-33217. It is possible to launch the attack remotely.
| Vendor | Product | Versions |
|---|---|---|
| go | github.com/nats-io/nats-server/v2 | go/github.com/nats-io/nats-server/v2: < 2.11.15, go/github.com/nats-io/nats-server/v2: >= 2.12.0-RC.1, < 2.12.6, go/github.com/nats-io/nats-server/v2: <= 2.11.14, go/github.com/nats-io/nats-server/v2: <= 2.12.5 |
Updated severity to CRITICAL, added affected versions up to 2.11.14 and 2.12.5, and noted that no exploit is available.
Initial creation