Information Disclosure Vulnerability in NATS-Server by NATS.io
CVE-2026-33247

7.4HIGH

Key Information:

Vendor

Nats-io

Vendor
CVE Published:
25 March 2026

What is CVE-2026-33247?

NATS-Server, a cloud and edge native messaging system, is susceptible to an information disclosure vulnerability when run with static credentials provided via command line arguments. Users who can access the monitoring port may inadvertently view sensitive credentials, as the '/debug/vars' endpoint exposes an unredacted version of the command-line arguments. To mitigate this issue, it is advised to avoid using command-line arguments for sensitive information, utilize a configuration file for credential management, and limit access to the monitoring port, especially from untrusted networks. Versions 2.11.15 and 2.12.6 have implemented necessary fixes to address this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

nats-server < 2.11.15 < 2.11.15

nats-server >= 2.12.0-RC.1, < 2.12.6 < 2.12.0-RC.1, 2.12.6

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.