NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nats
Nats nats Server |
|
| Vendors & Products |
Nats
Nats nats Server |
Tue, 24 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known workarounds are available. | |
| Title | NATS is vulnerable to MQTT hijacking via Client ID | |
| Weaknesses | CWE-287 CWE-488 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T13:05:12.279Z
Reserved: 2026-03-17T23:23:58.314Z
Link: CVE-2026-33215
Updated: 2026-03-25T13:05:05.816Z
Status : Awaiting Analysis
Published: 2026-03-24T21:16:28.640
Modified: 2026-03-25T15:41:58.280
Link: CVE-2026-33215
No data.
OpenCVE Enrichment
Updated: 2026-03-25T20:57:15Z