CVE-2026-33222

MEDIUM4.9EPSS 0.01%

NATS JetStream has an authorization bypass through its Management API

發布日:2026/3/24修改日:2026/3/27
也稱為:GHSA-9983-vrx2-fg9cBIT-nats-2026-33222CGA-jmv6-q4fp-447vGO-2026-4832

描述

### Background NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The persistent storage feature, JetStream, has a management API which has many features, amongst which are backup and restore. ### Problem Description Users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. ### Affected Versions Any version before v2.12.6 or v2.11.15 ### Workarounds If developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

受影響套件(6)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

參考連結(5)