NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
Description
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with verify_and_map to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypass. This does require a valid certificate from a CA already trusted for client certificates, and DN naming patterns which the NATS maintainers consider highly unlikely. So this is an unlikely attack. Nonetheless, administrators who have been very sophisticated in their DN construction patterns might conceivably be impacted. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, developers should review their CA issuing practices.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/nats-io/nats-server/v2Go | < 2.11.15 | 2.11.15 |
github.com/nats-io/nats-server/v2Go | >= 2.12.0-RC.1, < 2.12.6 | 2.12.6 |
github.com/nats-io/nats-serverGo | >= 0 | — |
Affected products
1- Range: < 2.11.15
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-3f24-pcvm-5jqcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-33248ghsaADVISORY
- advisories.nats.io/CVE/secnote-2026-13.txtghsax_refsource_MISCWEB
- github.com/nats-io/nats-server/security/advisories/GHSA-3f24-pcvm-5jqcghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.