Skip to content
nats-serverGHSA-pwx7-fx9r-hr4h

NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing

Medium6.4CVE-2026-33223 · Published Mar 24, 2026 · updated Sep 10, 2026

### Background NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The nats-server offers a `Nats-Request-Info:` message header, providing information about a request. ### Problem Description The NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from inbound messages was not fully effective. An attacker with valid credentials for any regular client interface could thus spoof their identity to services which rely upon this header. ### Affected Versions Any version before v2.12.6 or v2.11.15 ### Workarounds None.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/nats-io/nats-server
Go
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-290
Also known as
BIT-nats-2026-33223, CVE-2026-33223, GO-2026-4835

More nats-server advisories

All nats-server
Advisory
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
Medium4.2Mar 24
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
Medium6.4Mar 24
NATS JetStream has an authorization bypass through its Management API
Medium4.9Mar 24
NATS is vulnerable to pre-auth DoS through WebSockets client service
Medium5.3Mar 24
NATS has pre-auth server panic via leafnode handling
High7.5Mar 24
NATS allows MQTT clients to bypass ACL checks
High7.1Mar 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.