← Back

CVE-2026-33215

nvd nist
Published: Mar 24, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known workarounds are available.

Affected (2)

Nats Server
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Linuxfoundation
From 2.0.0 to 2.11.15
From 2.12.0 to 2.12.5

References (2)

Source: security-advisories@github.com
Broken Link
Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.