BIT-nats-2026-33249

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/nats/BIT-nats-2026-33249.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-nats-2026-33249
Aliases
Published
2026-03-30T11:45:25.356Z
Modified
2026-03-30T12:26:02.943661Z
Summary
NATS: Message tracing can be redirected to arbitrary subject
Details

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11.0 and prior to versions 2.11.15 and 2.12.6, a valid client which uses message tracing headers can indicate that the trace messages can be sent to an arbitrary valid subject, including those to which the client does not have publish permission. The payload is a valid trace message and not chosen by the attacker. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:nats:nats_server:*:*:*:*:*:go:*:*"
    ]
}
References

Affected packages

Bitnami / nats

Package

Name
nats
Purl
pkg:bitnami/nats

Severity

  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2.11.0
Fixed
2.11.15
Introduced
2.12.0
Fixed
2.12.6

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/nats/BIT-nats-2026-33249.json"