Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1401 articles · 106454 vulns · 36/55 feeds (7d)
← Back to list
6.4
CVE-2026-33246

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

Description

A vulnerability labeled as critical has been found in nats-io nats-server up to 2.11.14/2.12.5. This affects an unknown part of the component Nats-Request-Info Identity Header Handler. The manipulation results in authentication bypass by spoofing. This vulnerability is reported as CVE-2026-33246. The attack can be launched remotely.

Affected Products

VendorProductVersions
gogithub.com/nats-io/nats-server/v2go/github.com/nats-io/nats-server/v2: < 2.11.15, go/github.com/nats-io/nats-server/v2: >= 2.12.0-RC.1, < 2.12.6, up to 2.11.14, up to 2.12.5

References

  • https://github.com/advisories/GHSA-55h8-8g96-x4hj(advisory)
  • https://github.com/nats-io/nats-server/security/advisories/GHSA-55h8-8g96-x4hj
  • https://advisories.nats.io/CVE/secnote-2026-08.txt
  • https://github.com/advisories/GHSA-55h8-8g96-x4hj

Related News (1 articles)

Tier C
VulDB5h ago
CVE-2026-33246 | nats-io nats-server up to 2.11.14/2.12.5 Nats-Request-Info Identity Header authentication spoofing
→ No new info (linked only)
CVSS 3.16.4 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-287, CWE-290
Published3/24/2026
Last enriched3h agov2
Tags
GHSA-55h8-8g96-x4hjgo
Trending Score40
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Version History

v2
Last enriched 3h ago
v2Tier C3h ago

Updated severity to CRITICAL, added affected versions up to 2.11.14 and 2.12.5, and noted that no exploit exists.

descriptionaffectedVersionsseverityactivelyExploited
via VulDB
v111h ago

Initial creation