CVE-2026-33216

EUVD-2026-15964
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 29.25%
Affected Products (NVD)
VendorProductVersion
linuxfoundationnats-server
𝑥
< 2.11.15
linuxfoundationnats-server
2.12.0 ≤
𝑥
< 2.12.6
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatMulticluster Global Hub 1.5.4
1778867753 ≤
𝑥
< *
ADP
Red HatRed Hat multicluster global hub 1.4.4
1779579439 ≤
𝑥
< *
ADP
Red HatRed Hat multicluster global hub 1.6.0
1780167118 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
nats-server
bookworm
vulnerable
forky
2.14.3-1
fixed
sid
2.14.3-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nats-server
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
telegraf
Azure Linux 3.0
0:1.31.0-18.azl3
fixed