NATS operates a lightweight, open-source messaging and microservices communication platform whose core components—the NATS Server, NATS Streaming Server, and cryptographic libraries (JWT Library, NKeys)—are embedded across cloud-native and distributed systems. The recurring vulnerability signal centers on authentication and authorization gaps, path-traversal conditions, and cryptographic weaknesses including hard-coded keys and missing validation steps, reflecting the architectural priorities of a high-throughput message broker where access control and credential handling are foundational. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nats over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3127HIGH NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled. | Mar 16, 2021 | 7.5 | 24 | NO | NO |
CVE-2022-26652MEDIUM NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affe | Mar 10, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-24450HIGH NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox | Feb 8, 2022 | 8.8 | 22 | NO | NO |
CVE-2023-46129HIGH NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling lib | Oct 31, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nats.
Media articles that mention a CVE ID that affects a product developed by Nats — matched by CVE ID, not by vendor name.