Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

nats-server — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in nats-server, with AI-generated Chinese analysis, references, and POCs.

Vendor: nats-io

CVE IDTitleCVSSSeverityPublished
CVE-2026-33249 NATS: Message tracing can be redirected to arbitrary subject CWE-863 4.3 Medium2026-03-25
CVE-2026-33223 NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing CWE-290 6.4 Medium2026-03-25
CVE-2026-33248 NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching CWE-287 4.2 Medium2026-03-25
CVE-2026-33222 NATS JetStream has an authorization bypass through its Management API CWE-285 4.9 Medium2026-03-25
CVE-2026-33247 NATS credentials are exposed in monitoring port via command-line argv CWE-215 7.4 High2026-03-25
CVE-2026-33219 NATS is vulnerable to pre-auth DoS through WebSockets client service CWE-770 5.3 Medium2026-03-25
CVE-2026-33218 NATS has pre-auth server panic via leafnode handling CWE-20 7.5 High2026-03-25
CVE-2026-33246 NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers CWE-287 6.4 Medium2026-03-25
CVE-2026-33217 NATS allows MQTT clients to bypass ACL checks CWE-863 7.1 High2026-03-25
CVE-2026-33216 NATS has MQTT plaintext password disclosure CWE-256 8.6 High2026-03-25
CVE-2026-29785 NATS Server panic via malicious compression on leafnode port CWE-476 7.5 High2026-03-25
CVE-2026-27889 NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead CWE-190 7.5 High2026-03-25
CVE-2026-33215 NATS is vulnerable to MQTT hijacking via Client ID CWE-287 6.5 Medium2026-03-24
CVE-2026-27571 nats-server websockets are vulnerable to pre-auth memory DoS CWE-409 5.9 Medium2026-02-24
CVE-2025-30215 NATS-Server Fails to Authorize Certain Jetstream Admin APIs CWE-306 9.6 Critical2025-04-15

All 15 known CVE vulnerabilities affecting nats-server with full Chinese analysis, references, and POCs where available.