Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33216

Опубликовано: 25 мар. 2026
Источник: redhat
CVSS3: 8.6
EPSS Низкий

Описание

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.

A flaw was found in NATS-Server, a high-performance server for the NATS.io messaging system. For MQTT deployments utilizing usercodes and passwords, the MQTT passwords were mistakenly categorized as non-authenticating identity statements (JSON Web Tokens - JWT). This misclassification leads to the exposure of these passwords through monitoring endpoints, enabling an attacker with access to these endpoints to gain sensitive information.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/oc-mirror-plugin-rhel9Not affected
Multicluster Global Hub 1.5.4multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:2176928.05.2026
Red Hat multicluster global hub 1.4.4multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:2234701.06.2026
Red Hat multicluster global hub 1.6.0multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:2334504.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-213
https://bugzilla.redhat.com/show_bug.cgi?id=2451448nats-server: github.com/nats-io/nats-server: NATS-Server: Information disclosure of MQTT passwords through monitoring endpoints

EPSS

Процентиль: 29%
0.00365
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
4 месяца назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.

CVSS3: 8.6
nvd
4 месяца назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.

CVSS3: 8.6
msrc
4 месяца назад

NATS has MQTT plaintext password disclosure

CVSS3: 8.6
debian
4 месяца назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

CVSS3: 8.6
github
5 месяцев назад

NATS has MQTT plaintext password disclosure

EPSS

Процентиль: 29%
0.00365
Низкий

8.6 High

CVSS3