NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known workarounds are available.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fcjp-h8cc-6879 | NATS is vulnerable to MQTT hijacking via Client ID |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 24 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known workarounds are available. | |
| Title | NATS is vulnerable to MQTT hijacking via Client ID | |
| Weaknesses | CWE-287 CWE-488 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-24T20:55:53.455Z
Reserved: 2026-03-17T23:23:58.314Z
Link: CVE-2026-33215
No data.
Status : Received
Published: 2026-03-24T21:16:28.640
Modified: 2026-03-24T21:16:28.640
Link: CVE-2026-33215
No data.
OpenCVE Enrichment
No data.
Github GHSA