github.com/nats-io/nats-server/v2 vulnerabilities
CVEs whose affected-version data names the github.com/nats-io/nats-server/v2 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-33246Medium· 6.4NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
▾ Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 0.14%via OSV
CVE-2026-33248Medium· 4.2NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
▾ Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 0.14%via OSV
CVE-2023-47090HighNATS.io: Adding accounts for just the system account adds auth bypass
NATS.io: Adding accounts for just the system account adds auth bypass
▾ Twilightnats-io · github.com/nats-io/nats-server/v2EPSS 0.66%via OSV
CVE-2022-26652Medium· 6.5Arbitrary file write in nats-server
Arbitrary file write in nats-server
▾ Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 2.3%via OSV
CVE-2020-28466High· 7.5Denial of service in github.com/nats-io/nats-server/server
Denial of service in github.com/nats-io/nats-server/server
▾ Twilightnats-io · github.com/nats-io/nats-serverEPSS 3.7%via OSV