CVE-2026-33249

MEDIUM4.3EPSS 0.01%

NATS: Message tracing can be redirected to arbitrary subject

發布日:2026/3/24修改日:2026/3/30
也稱為:GHSA-8m2x-3m6q-6w8jBIT-nats-2026-33249CGA-j4q2-4fxj-9r3hGO-2026-4826

描述

### Background NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The nats-server supports telemetry on messages, using the per-message NATS headers. ### Problem Description A valid client which uses message tracing headers can indicate that the trace messages can be sent to an arbitrary valid subject, including those to which the client does not have publish permission. The payload is a valid trace message and not chosen by the attacker. ### Affected Versions Any version before v2.12.6 or v2.11.15 ### Workarounds None.

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

參考連結(5)