VulnSea

nats-io has 7 CVEs on record between 2022 and 2026. The median CVSS is 6.5 (medium), with 2 rated critical. None have a confirmed exploitation report. Most affected products: github.com/nats-io/nats-server/v2 (4), github.com/nats-io/jwt (2), github.com/nats-io/nats-server (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
0 prev 0

Products

  • github.com/nats-io/nats-server/v2 4
  • github.com/nats-io/jwt 2
  • github.com/nats-io/nats-server 1
7
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

nats-io vulnerabilities

CVEs affecting nats-io, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-33246Medium· 6.4
6mo ago

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 0.14%via OSV
CVE-2026-33248Medium· 4.2
6mo ago

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 0.14%via OSV
CVE-2023-47090High
2y ago

NATS.io: Adding accounts for just the system account adds auth bypass

NATS.io: Adding accounts for just the system account adds auth bypass

Twilightnats-io · github.com/nats-io/nats-server/v2EPSS 0.66%via OSV
CVE-2022-26652Medium· 6.5
4y ago

Arbitrary file write in nats-server

Arbitrary file write in nats-server

Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 2.3%via OSV
CVE-2021-3127Critical
4y ago

nats-io/jwt not enforcing checking of Import token permissions

nats-io/jwt not enforcing checking of Import token permissions

Midnightnats-io · github.com/nats-io/jwtEPSS 1.4%via OSV
CVE-2020-28466High· 7.5
4y ago

Denial of service in github.com/nats-io/nats-server/server

Denial of service in github.com/nats-io/nats-server/server

Twilightnats-io · github.com/nats-io/nats-serverEPSS 3.7%via OSV
CVE-2020-26892Critical· 9.8
4y ago

Incorrect handling of credential expiry by /nats-io/nats-server

Incorrect handling of credential expiry by /nats-io/nats-server

Midnightnats-io · github.com/nats-io/jwtEPSS 2.1%via OSV
nats-io vulnerabilities (CVEs) · VulnSea