Technology · Go
github.com/nats-io/nats-server/v2 (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 29 vulnerabilities in github.com/nats-io/nats-server/v2 (Go): 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-33246, was published on 26 March 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 0
About github.com/nats-io/nats-server/v2 (Go)
NATS Server is a high-performance messaging system for cloud-native applications, IoT messaging, and microservices architectures.
Latest github.com/nats-io/nats-server/v2 (Go) vulnerabilities
- CVE-2026-33246: GO-2026-4830 - NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers in…lowCVSS 3.1EPSS 0.2%
- CVE-2026-33215: GO-2026-4833 - NATS is vulnerable to MQTT hijacking via Client ID in github.com/nats-io/nats-serverlowCVSS 3.1EPSS 0.3%
- CVE-2026-33223: GO-2026-4835 - NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing in…lowCVSS 3.1EPSS 0.2%
- CVE-2026-33222: GO-2026-4832 - NATS JetStream has an authorization bypass through its Management API in github.com/nats-io/nats-serverlowCVSS 3.1EPSS 0.3%
- CVE-2026-33249: GO-2026-4826 - NATS: Message tracing can be redirected to arbitrary subject in github.com/nats-io/nats-serverlowCVSS 3.1EPSS 0.3%
- CVE-2026-33248: GO-2026-4828 - NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching in…lowCVSS 3.1EPSS 0.2%
- CVE-2026-33247: NATS-Server sensitive information disclosure in monitoring endpointhighCVSS 7.4EPSS 0.5%
- CVE-2026-33219: NATS-Server denial of service in WebSockets componentmediumCVSS 5.3EPSS 1.0%
- CVE-2026-33218: NATS-Server denial of service in leafnode handlinghighCVSS 7.5EPSS 0.8%
- CVE-2026-33217: NATS-Server ACL bypass in MQTT namespacehighCVSS 7.1EPSS 0.4%
- CVE-2026-33216: NATS-Server plaintext password disclosure in monitoring endpointshighCVSS 8.6EPSS 0.6%
- CVE-2026-29785: nats-io nats-server NULL pointer dereference in leafnode protocolhighCVSS 7.5EPSS 1.0%
- CVE-2026-27889: NATS Server denial of service via WebSocket frame length overflowhighCVSS 7.5EPSS 0.8%
- CVE-2026-27571: GO-2026-4533 - nats-server websockets are vulnerable to pre-auth memory DoS in github.com/nats-io/nats-serverlowCVSS 3.1EPSS 0.7%
- CVE-2025-30215: NATS Server authorization bypass in JetStream admin APIscriticalCVSS 9.6EPSS 0.6%
- CVE-2019-13126: GO-2022-0852 - Integer Overflow or Wraparound in NATS Server in github.com/nats-io/nats-serverlowCVSS 3.1EPSS 1.8%
- CVE-2020-28466: GO-2022-0855 - Denial of service in github.com/nats-io/nats-server/server in github.com/nats-io/nats-serverlowCVSS 3.1EPSS 3.7%
- GO-2022-0398 - Import loops in account imports, nats-server DoS in github.com/nats-io/nats-serverinfo
- CVE-2022-26652: GO-2022-0351 - Arbitrary file write in nats-server in github.com/nats-io/nats-serverlowCVSS 3.1EPSS 2.3%
- CVE-2022-24450: GO-2022-0307 - Incorrect Authorization in NATS nats-server in github.com/nats-io/nats-serverlowCVSS 3.1EPSS 1.3%
- CVE-2022-28357: GO-2023-2066 - NATS nats-server allows directory traversal via unintended path to a management action in…lowCVSS 3.1EPSS 1.2%
- CVE-2022-29946: GO-2024-2980 - NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjects in…lowCVSS 3.1EPSS 0.5%
- CVE-2021-32026: GO-2024-2850 - NATS server TLS missing ciphersuite settings when CLI flags used in github.com/nats-io/nats-serverinfo
- CVE-2023-46129: GO-2023-2163 - Curve KeyPairs fail to encrypt in github.com/nats-io/nkeyslowCVSS 3.1EPSS 0.4%
- CVE-2023-47090: GO-2023-2133 - Authorization bypass in github.com/nats-io/nats-server/v2infoEPSS 0.7%
Most severe github.com/nats-io/nats-server/v2 (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-30215: NATS Server authorization bypass in JetStream admin APIscriticalCVSS 9.6EPSS 0.6%
- CVE-2026-33216: NATS-Server plaintext password disclosure in monitoring endpointshighCVSS 8.6EPSS 0.6%
- CVE-2026-29785: nats-io nats-server NULL pointer dereference in leafnode protocolhighCVSS 7.5EPSS 1.0%
- CVE-2026-33218: NATS-Server denial of service in leafnode handlinghighCVSS 7.5EPSS 0.8%
- CVE-2026-27889: NATS Server denial of service via WebSocket frame length overflowhighCVSS 7.5EPSS 0.8%
- CVE-2026-33247: NATS-Server sensitive information disclosure in monitoring endpointhighCVSS 7.4EPSS 0.5%
- CVE-2026-33217: NATS-Server ACL bypass in MQTT namespacehighCVSS 7.1EPSS 0.4%
- CVE-2026-33219: NATS-Server denial of service in WebSockets componentmediumCVSS 5.3EPSS 1.0%
- CVE-2020-28466: GO-2022-0855 - Denial of service in github.com/nats-io/nats-server/server in github.com/nats-io/nats-serverlowCVSS 3.1EPSS 3.7%
- CVE-2022-26652: GO-2022-0351 - Arbitrary file write in nats-server in github.com/nats-io/nats-serverlowCVSS 3.1EPSS 2.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-nats-io-nats-server-v2.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/nats-io/nats-server/v2 (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-nats-io-nats-server-v2, 27 September 2026.