| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fcjp-h8cc-6879 | NATS is vulnerable to MQTT hijacking via Client ID |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 25 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nats
Nats nats Server |
|
| Vendors & Products |
Nats
Nats nats Server |
Tue, 24 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known workarounds are available. | |
| Title | NATS is vulnerable to MQTT hijacking via Client ID | |
| Weaknesses | CWE-287 CWE-488 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T13:05:12.279Z
Reserved: 2026-03-17T23:23:58.314Z
Link: CVE-2026-33215
Updated: 2026-03-25T13:05:05.816Z
Status : Awaiting Analysis
Published: 2026-03-24T21:16:28.640
Modified: 2026-03-25T15:41:58.280
Link: CVE-2026-33215
No data.
OpenCVE Enrichment
Updated: 2026-03-25T11:45:49Z
Github GHSA