NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
Medium4.2CVE-2026-33248 · Published Mar 24, 2026 · updated Sep 10, 2026
### Background NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. One authentication model supported is mTLS, deriving the NATS client identity from properties of the TLS Client Certificate. ### Problem Description When using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypass. This does require a valid certificate from a CA already trusted for client certificates, and `DN` naming patterns which the NATS maintainers consider highly unlikely. So this is an unlikely attack. Nonetheless, administrators who have been very sophisticated in their `DN` construction patterns might conceivably be impacted. ### Affected Versions Fixed in nats-server 2.12.6 & 2.11.15 ### Workarounds Developers should review their CA issuing practices.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/nats-io/nats-server Go | all versions | No fix yet |
Details and references
More nats-server advisories
All nats-server| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 24 | NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers | Medium6.4 | No fix yet |
| Mar 24 | NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing | Medium6.4 | No fix yet |
| Mar 24 | NATS JetStream has an authorization bypass through its Management API | Medium4.9 | No fix yet |
| Mar 24 | NATS is vulnerable to pre-auth DoS through WebSockets client service | Medium5.3 | No fix yet |
| Mar 24 | NATS has pre-auth server panic via leafnode handling | High7.5 | No fix yet |
| Mar 24 | NATS allows MQTT clients to bypass ACL checks | High7.1 | No fix yet |