---
id: CVE-2026-33246
aliases:
  - GHSA-55h8-8g96-x4hj
  - BIT-nats-2026-33246
  - GO-2026-4830
title: >-
  NATS: Leafnode connections allow spoofing of Nats-Request-Info identity
  headers
summary: >-
  NATS: Leafnode connections allow spoofing of Nats-Request-Info identity
  headers
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
vendor: nats-io
product: github.com/nats-io/nats-server/v2
ecosystem: go
affected:
  - github.com/nats-io/nats-server/v2 < 2.11.15
  - 'github.com/nats-io/nats-server/v2 >= 2.12.0-RC.1, < 2.12.6'
  - github.com/nats-io/nats-server
patched:
  - github.com/nats-io/nats-server/v2 2.11.15
  - github.com/nats-io/nats-server/v2 2.12.6
published: '2026-03-24'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:59.829737231Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-55h8-8g96-x4hj'
references:
  - url: >-
      https://github.com/nats-io/nats-server/security/advisories/GHSA-55h8-8g96-x4hj
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33246'
  - url: 'https://advisories.nats.io/CVE/secnote-2026-08.txt'
  - url: 'https://github.com/nats-io/nats-server'
tags:
  - osv
  - go
epss: 0.00143
epssPercentile: 0.03983
ingestedAt: '2026-09-12T03:13:01.754Z'
---

## Overview

### Background

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.

The nats-server allows hub/spoke topologies using "leafnode" connections by other nats-servers.  NATS messages can have headers.

### Problem Description

The nats-server offers a `Nats-Request-Info:` message header, providing information about a request.  This is supposed to provide enough information to allow for account/user identification, such that NATS clients could make their own decisions on how to trust a message, provided that they trust the nats-server as a broker.

A leafnode connecting to a nats-server is not fully trusted unless the system account is bridged too.  Thus identity claims should not have propagated unchecked.

Thus NATS clients relying upon the Nats-Request-Info: header could be spoofed.

Does not directly affect the nats-server itself, but the CVSS Confidentiality and Integrity scores are based upon what a hypothetical client might choose to do with this NATS header.

### Affected Versions

Any version before v2.12.6 or v2.11.15

### Workarounds

None.

## Affected packages

- `github.com/nats-io/nats-server/v2 < 2.11.15`
- `github.com/nats-io/nats-server/v2 >= 2.12.0-RC.1, < 2.12.6`
- `github.com/nats-io/nats-server`

## Remediation

Upgrade to a patched release:

- `github.com/nats-io/nats-server/v2 2.11.15`
- `github.com/nats-io/nats-server/v2 2.12.6`
