{"id":"CVE-2026-33246","aliases":["GHSA-55h8-8g96-x4hj","BIT-nats-2026-33246","GO-2026-4830"],"title":"NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers","summary":"NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","vendor":"nats-io","product":"github.com/nats-io/nats-server/v2","ecosystem":"go","affected":["github.com/nats-io/nats-server/v2 < 2.11.15","github.com/nats-io/nats-server/v2 >= 2.12.0-RC.1, < 2.12.6","github.com/nats-io/nats-server"],"patched":["github.com/nats-io/nats-server/v2 2.11.15","github.com/nats-io/nats-server/v2 2.12.6"],"published":"2026-03-24","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:59.829737231Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-55h8-8g96-x4hj","references":[{"url":"https://github.com/nats-io/nats-server/security/advisories/GHSA-55h8-8g96-x4hj"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33246"},{"url":"https://advisories.nats.io/CVE/secnote-2026-08.txt"},{"url":"https://github.com/nats-io/nats-server"}],"tags":["osv","go"],"epss":0.00143,"epssPercentile":0.03986,"ingestedAt":"2026-09-12T03:13:01.754Z","slug":"CVE-2026-33246","body":"## Overview\n\n### Background\n\nNATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.\n\nThe nats-server allows hub/spoke topologies using \"leafnode\" connections by other nats-servers.  NATS messages can have headers.\n\n### Problem Description\n\nThe nats-server offers a `Nats-Request-Info:` message header, providing information about a request.  This is supposed to provide enough information to allow for account/user identification, such that NATS clients could make their own decisions on how to trust a message, provided that they trust the nats-server as a broker.\n\nA leafnode connecting to a nats-server is not fully trusted unless the system account is bridged too.  Thus identity claims should not have propagated unchecked.\n\nThus NATS clients relying upon the Nats-Request-Info: header could be spoofed.\n\nDoes not directly affect the nats-server itself, but the CVSS Confidentiality and Integrity scores are based upon what a hypothetical client might choose to do with this NATS header.\n\n### Affected Versions\n\nAny version before v2.12.6 or v2.11.15\n\n### Workarounds\n\nNone.\n\n## Affected packages\n\n- `github.com/nats-io/nats-server/v2 < 2.11.15`\n- `github.com/nats-io/nats-server/v2 >= 2.12.0-RC.1, < 2.12.6`\n- `github.com/nats-io/nats-server`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/nats-io/nats-server/v2 2.11.15`\n- `github.com/nats-io/nats-server/v2 2.12.6`","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}