CVE 6.5 MEDIUM

NATS is vulnerable to MQTT hijacking via Client ID_CVE-2026-33215

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L

Description

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known workarounds are available.

Basic Information

ID CVE-2026-33215
Source GitHub_M
Published Mar 24, 2026 at 20:55
Modified Mar 25, 2026 at 13:05

Affected Product

Vendor nats-io
Product nats-server
Version < 2.11.15
Affected Versions nats-io nats-server < 2.11.15
nats-io nats-server >= 2.12.0-RC.1, < 2.12.6

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.