Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1406 articles · 106464 vulns · 36/55 feeds (7d)
← Back to list
4.2
CVE-2026-33248

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

Description

A vulnerability marked as critical has been reported in nats-io nats-server up to 2.11.14/2.12.5. This vulnerability affects the function verify_and_map of the component mTLS. This manipulation causes improper certificate validation. The attack may be initiated remotely.

Affected Products

VendorProductVersions
gogithub.com/nats-io/nats-server/v2go/github.com/nats-io/nats-server/v2: < 2.11.15, go/github.com/nats-io/nats-server/v2: >= 2.12.0-RC.1, < 2.12.6, go/github.com/nats-io/nats-server/v2: <= 2.11.14, go/github.com/nats-io/nats-server/v2: <= 2.12.5

References

  • https://github.com/advisories/GHSA-3f24-pcvm-5jqc(advisory)
  • https://github.com/nats-io/nats-server/security/advisories/GHSA-3f24-pcvm-5jqc
  • https://advisories.nats.io/CVE/secnote-2026-13.txt
  • https://github.com/advisories/GHSA-3f24-pcvm-5jqc

Related News (1 articles)

Tier C
VulDB5h ago
CVE-2026-33248 | nats-io nats-server up to 2.11.14/2.12.5 mTLS verify_and_map certificate validation
→ No new info (linked only)
CVSS 3.14.2 CRITICAL
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-287, CWE-295
Published3/24/2026
Last enriched3h agov2
Tags
GHSA-3f24-pcvm-5jqcgoCVE-2026-33248
Trending Score40
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Version History

v2
Last enriched 3h ago
v2Tier C3h ago

Updated severity to CRITICAL, added affected versions up to 2.11.14/2.12.5, and noted that the vulnerability is actively exploited.

descriptionaffectedVersionsseverityactivelyExploitedtags
via VulDB
v111h ago

Initial creation