CVE-2026-33222
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system.
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.31% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- linuxfoundation/nats-server
- Source
- security-advisories@github.com
References
- https://advisories.nats.io/CVE/secnote-2026-12.txtMitigation, Vendor Advisory
- https://github.com/nats-io/nats-server/security/advisories/GHSA-9983-vrx2-fg9cMitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.