Home

Description

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

PUBLISHED Reserved 2026-03-17 | Published 2026-03-25 | Updated 2026-03-26 | Assigner GitHub_M




MEDIUM: 4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Problem types

CWE-285: Improper Authorization

Product status

< 2.11.15
affected

>= 2.12.0-RC.1, < 2.12.6
affected

References

github.com/...server/security/advisories/GHSA-9983-vrx2-fg9c

advisories.nats.io/CVE/secnote-2026-12.txt

cve.org (CVE-2026-33222)

nvd.nist.gov (CVE-2026-33222)

Download JSON