<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T22:35:21.582473+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-nats-2021-3127</id>
    <title>BIT-nats-2021-3127</title>
    <updated>2026-10-07T22:35:21.667020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: nats</p>
<p>NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-nats-2021-3127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-26378</id>
    <title>cnvd-2021-26378</title>
    <updated>2026-10-07T22:35:21.667074+00:00</updated>
    <content>cnvd-2021-26378</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-26378"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-20699</id>
    <title>EUVD-2026-20699</title>
    <updated>2026-10-07T22:35:21.667092+00:00</updated>
    <content>EUVD-2026-20699</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-20699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3127</id>
    <title>fkie_cve-2021-3127</title>
    <updated>2026-10-07T22:35:21.667104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-62mh-w5cv-p88c</id>
    <title>GHSA-62mh-w5cv-p88c — nats-io/jwt not enforcing checking of Import token permissions</title>
    <updated>2026-10-07T22:35:21.667126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/nats-io/jwt, Go: github.com/nats-io/jwt/v2</p>
<p>(This advisory is canonically &lt;https://advisories.nats.io/CVE/CVE-2021-3127.txt&gt;)</p>
<p>## Problem Description</p>
<p>The NATS server provides for Subjects which are namespaced by Account; all Subjects are supposed to be private to an account, with an Export/Import system used to grant cross-account access to some Subjects.  Some Exports are public, such that anyone can import the
relevant subjects, and some Exports are private, such that the Import requires a token JWT to prove permission.</p>
<p>The JWT library's validation of the bindings in the Import Token incorrectly warned on mismatches, instead of outright rejecting the token.</p>
<p>As a result, any account can take an Import token used by any other account and re-use it for themselves because the binding to the
importing account is not rejected, and use it to import *any* Subject from the Exporting account, not just the Subject referenced in the Import Token.</p>
<p>The NATS account-server system treats account JWTs as semi-public information, such that an attacker can easily enumerate all account JWTs and retrieve all Import Tokens from those account JWTs.</p>
<p>The CVE identifier should cover the JWT library repair and the nats-server containing the fixed JWT library, and any other application depending upon the fixed JWT library.</p>
<p>## Affected versions</p>
<p>#### JWT library</p>
<p>* all versions prior to 2.0.1
 * fixed after nats-io/jwt#149 landed (2021-03-14)</p>
<p>#### NATS Server</p>
<p>* Version 2 prior to 2.2.0
   + 2.0.0 through and including 2.1.9 are vulne…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-62mh-w5cv-p88c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3127</id>
    <title>gsd-2021-3127</title>
    <updated>2026-10-07T22:35:21.667175+00:00</updated>
    <content>gsd-2021-3127</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3127</id>
    <title>UBUNTU-CVE-2021-3127</title>
    <updated>2026-10-07T22:35:21.667187+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: golang-github-nats-io-jwt, Ubuntu:22.04:LTS: golang-github-nats-io-jwt</p>
<p>NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3127"/>
  </entry>
</feed>
