Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33216

Опубликовано: 25 мар. 2026
Источник: nvd
CVSS3: 8.6
CVSS3: 7.5
EPSS Низкий

Описание

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
Версия до 2.11.15 (исключая)
cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
Версия от 2.12.0 (включая) до 2.12.6 (исключая)

EPSS

Процентиль: 29%
0.00365
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-256
CWE-213

Связанные уязвимости

CVSS3: 8.6
ubuntu
4 месяца назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.

CVSS3: 8.6
redhat
4 месяца назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.

CVSS3: 8.6
msrc
4 месяца назад

NATS has MQTT plaintext password disclosure

CVSS3: 8.6
debian
4 месяца назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

CVSS3: 8.6
github
5 месяцев назад

NATS has MQTT plaintext password disclosure

EPSS

Процентиль: 29%
0.00365
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-256
CWE-213