CVE-2026-33223
Last modified
CVE-2026-33223 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from inbound messages was not fully effective. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from inbound messages was not fully effective. An attacker with valid credentials for any regular client interface could thus spoof their identity to services which rely upon this header. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Nats-Server | < 2.11.15 |
| Linuxfoundation | Nats-Server | >= 2.12.0, < 2.12.6 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33223?
How severe is CVE-2026-33223?
How do I fix CVE-2026-33223?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33217NATS-Server is a High-Performance server for NATS.io, a clou…6.5
- CVE-2026-33218NATS-Server is a High-Performance server for NATS.io, a clou…7.5
- CVE-2026-33219NATS-Server is a High-Performance server for NATS.io, a clou…5.3
- CVE-2026-33220Weblate is a web based localization tool. In versions prior …6.8
- CVE-2026-33221Nhost is an open source Firebase alternative with GraphQL. P…5.3
- CVE-2026-33222NATS-Server is a High-Performance server for NATS.io, a clou…4.9
- CVE-2026-33226Budibase is a low code platform for creating internal tools,…8.7
- CVE-2026-33227Improper validation and restriction of a classpath path name…4.3
- CVE-2026-33228flatted is a circular JSON parser. Prior to version 3.4.2, t…9.8
- CVE-2026-33229XWiki Platform is a generic wiki platform offering runtime s…9.8
- CVE-2026-3323An unsecured configuration interface on affected devices all…7.5
- CVE-2026-33230NLTK (Natural Language Toolkit) is a suite of open source Py…6.1
Are you affected by CVE-2026-33223?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
