SCA: security update for github.com/nats-io/nats-server/v2 (GHSA-3f24-pcvm-5jqc)

medium Tenable Self-Hosted Container Security Plugin ID 439153

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to
versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS
identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly
enforced, allowing for authentication bypass. This does require a valid certificate from a CA already
trusted for client certificates, and `DN` naming patterns which the NATS maintainers consider highly
unlikely. So this is an unlikely attack. Nonetheless, administrators who have been very sophisticated in
their `DN` construction patterns might conceivably be impacted. Versions 2.11.15 and 2.12.6 contain a fix.
As a workaround, developers should review their CA issuing practices. (CVE-2026-33248)

Solution

Update the github.com/nats-io/nats-server/v2 library and its related packages to version 2.11.15 or later.

See Also

https://github.com/advisories/GHSA-3f24-pcvm-5jqc

Plugin Details

Severity: Medium

ID: 439153

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 3/25/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.71

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 3.6

Temporal Score: 2.7

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-33248

CVSS v3

Risk Factor: Medium

Base Score: 4.2

Temporal Score: 3.7

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/24/2026

Vulnerability Publication Date: 3/24/2026

Reference Information

CVE: CVE-2026-33248