GHSA-55h8-8g96-x4hj · Severity: medium · Ecosystem: go — NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message header, providing information about a request. This is supposed to provide enough information to allow for account/user identification, such that NATS clients could make their own decisions on how to trust a message, provided that they trust the nats-server as a broker. A leafnode connecting to a nats-server is not fully trusted unless the system account is bridged too. Thus identity claims should not have propagated unchecked. Prior to versions 2.11.15 and 2.12.6, NATS clients relying upon the Nats-Request-Info: header could be spoofed. This does not directly affect the nats-server itself, but the CVSS Confidentiality and Integrity scores are based upon what a hypothetical client might choose to do with this NATS header. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.
Conclusion & alert: CVE-2026-33246 is rated Low Risk (28/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.03%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-26 | — | 0.03% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.4 | 3.1 | MEDIUM |
|
3.1 | 2.7 | [email protected] |
| 5.4 | 3.1 | MEDIUM |
|
2.8 | 2.5 | [email protected] |
GHSA-55h8-8g96-x4hj · Severity: medium · Ecosystem: go — NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2026-33246: 1 source package rows (nats-server); 39 state rows across 2 repos (3.23-community, edge-community); fixed 2, open 37. | https://security.alpinelinux.org/vuln/CVE-2026-33246 |
debian
|
not yet assigned | CVE-2026-33246 not yet assigned priority: Debian including 1 source packages (nats-server), 4 status rows across 4 suites (bookworm, forky, sid, trixie): open 2, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2026-33246 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2026-33246 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2026-33246/ |
ubuntu
|
medium | CVE-2026-33246 medium priority: Ubuntu including 1 source packages (nats-server), 4 status rows across 4 suites (jammy, noble, questing, upstream): needs-triage 3, DNE 1. | https://ubuntu.com/security/CVE-2026-33246 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linuxfoundation | nats-server | < 2.11.15 | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* |
| linuxfoundation | nats-server | >= 2.12.0, < 2.12.6 | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://advisories.nats.io/CVE/secnote-2026-08.txt | Vendor Advisory |
| https://github.com/nats-io/nats-server/security/advisories/GHSA-55h8-8g96-x4hj | Vendor Advisory |