Junglewise Threat Intelligence

NATS nats.js TLS credential disclosure in CONNECT message

Severity: info · CVSS 7.5 · Published 2021-04-06

Vendors: NATS, npm.

Executive brief

The NATS nats.js client library inadvertently sends TLS client certificate private keys to the NATS server as part of the connection handshake. For applications using mutual TLS authentication, this means an attacker controlling or eavesdropping on the server can intercept the client's cryptographic credentials, enabling impersonation or decryption of communications. The risk is highest when the server is untrusted or TLS verification is disabled.

Technical details

The vulnerability is an information disclosure flaw (CWE-522) in JavaScript NATS client libraries where connection configuration options—including TLS private key material—are fully serialized and sent to the server in the client's CONNECT message immediately after TLS establishment. The nats.js client supports mutual TLS, causing private credentials to leak. The flaw affects only preview/beta versions (nats.js 2.0.0-201 through 2.0.0-208); mainline is unaffected. Attack requires network access to intercept or control the NATS server, and applies only to deployments using mutual TLS. An attacker with access to the server can extract the TLS client private key and authenticate or eavesdrop on the client. Fixes are available in nats.js 2.0.0-209 and later; users must also reissue and revoke TLS credentials.

Affected products

  • NATS nats.js 2.0.0-201 through 2.0.0-208 (beta branch)
  • NATS nats.ws 1.0.0-85 through 1.0.0-110 (preview)
  • NATS nats.deno all git tags prior to v1.0.0-9 (preview)

Timeline

  • 2020-09-29: disclosed: NATS advisory published
  • 2021-04-06: advisory: GHSA-prmc-5v5w-c465 published
  • 2020-09-29: patched: nats.js 2.0.0-209, nats.ws 1.0.0-111, nats.deno v1.0.0-9 fixed the issue

References

Related threats