CVE-2026-33247 affects NATS-Server versions prior to 2.11.15 and 2.12.6, allowing for the disclosure of static credentials. This vulnerability occurs when credentials are provided via command-line arguments and the monitoring port is enabled, exposing them unredacted through the /debug/vars endpoint to any user with monitoring port access. Rated Medium (CVSS 5.3), this vulnerability has a high confidentiality impact but requires specific configuration and network access, indicating high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community attention, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.15CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* | ||
>= 2.12.0, < 2.12.6CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.