Skip to content
nats-serverGHSA-3f24-pcvm-5jqc

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

Medium4.2CVE-2026-33248 · Published Mar 24, 2026 · updated Sep 10, 2026

### Background NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. One authentication model supported is mTLS, deriving the NATS client identity from properties of the TLS Client Certificate. ### Problem Description When using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypass. This does require a valid certificate from a CA already trusted for client certificates, and `DN` naming patterns which the NATS maintainers consider highly unlikely. So this is an unlikely attack. Nonetheless, administrators who have been very sophisticated in their `DN` construction patterns might conceivably be impacted. ### Affected Versions Fixed in nats-server 2.12.6 & 2.11.15 ### Workarounds Developers should review their CA issuing practices.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/nats-io/nats-server
Go
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287, CWE-295
Also known as
BIT-nats-2026-33248, CVE-2026-33248, GO-2026-4828

More nats-server advisories

All nats-server
Advisory
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
Medium6.4Mar 24
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
Medium6.4Mar 24
NATS JetStream has an authorization bypass through its Management API
Medium4.9Mar 24
NATS is vulnerable to pre-auth DoS through WebSockets client service
Medium5.3Mar 24
NATS has pre-auth server panic via leafnode handling
High7.5Mar 24
NATS allows MQTT clients to bypass ACL checks
High7.1Mar 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.