NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
Medium6.4CVE-2026-33223 · Published Mar 24, 2026 · updated Sep 10, 2026
### Background NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The nats-server offers a `Nats-Request-Info:` message header, providing information about a request. ### Problem Description The NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from inbound messages was not fully effective. An attacker with valid credentials for any regular client interface could thus spoof their identity to services which rely upon this header. ### Affected Versions Any version before v2.12.6 or v2.11.15 ### Workarounds None.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/nats-io/nats-server Go | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-290
- Also known as
- BIT-nats-2026-33223, CVE-2026-33223, GO-2026-4835
More nats-server advisories
All nats-server| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 24 | NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching | Medium4.2 | No fix yet |
| Mar 24 | NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers | Medium6.4 | No fix yet |
| Mar 24 | NATS JetStream has an authorization bypass through its Management API | Medium4.9 | No fix yet |
| Mar 24 | NATS is vulnerable to pre-auth DoS through WebSockets client service | Medium5.3 | No fix yet |
| Mar 24 | NATS has pre-auth server panic via leafnode handling | High7.5 | No fix yet |
| Mar 24 | NATS allows MQTT clients to bypass ACL checks | High7.1 | No fix yet |