<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:06:34.314007+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-nats-2026-33248</id>
    <title>BIT-nats-2026-33248 — NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching</title>
    <updated>2026-10-03T08:06:34.411846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: nats</p>
<p>NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypass. This does require a valid certificate from a CA already trusted for client certificates, and `DN` naming patterns which the NATS maintainers consider highly unlikely. So this is an unlikely attack. Nonetheless, administrators who have been very sophisticated in their `DN` construction patterns might conceivably be impacted. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, developers should review their CA issuing practices.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-nats-2026-33248"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-yk24413</id>
    <title>CLEANSTART-2026-YK24413 — Security fix for CVE-2026-33248 applied in: nats-server-fips 2.12.5-r1</title>
    <updated>2026-10-03T08:06:34.411995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: nats-server-fips</p>
<p>Security vulnerability affects the nats-server-fips package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-yk24413"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277686</id>
    <title>EUVD-2026-277686</title>
    <updated>2026-10-03T08:06:34.412022+00:00</updated>
    <content>EUVD-2026-277686</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277686"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33248</id>
    <title>fkie_cve-2026-33248</title>
    <updated>2026-10-03T08:06:34.412037+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypass. This does require a valid certificate from a CA already trusted for client certificates, and `DN` naming patterns which the NATS maintainers consider highly unlikely. So this is an unlikely attack. Nonetheless, administrators who have been very sophisticated in their `DN` construction patterns might conceivably be impacted. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, developers should review their CA issuing practices.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33248"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3f24-pcvm-5jqc</id>
    <title>GHSA-3f24-pcvm-5jqc — NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching</title>
    <updated>2026-10-03T08:06:34.412074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/nats-io/nats-server/v2, Go: github.com/nats-io/nats-server</p>
<p>### Background</p>
<p>NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.</p>
<p>One authentication model supported is mTLS, deriving the NATS client identity from properties of the TLS Client Certificate.</p>
<p>### Problem Description</p>
<p>When using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypass.</p>
<p>This does require a valid certificate from a CA already trusted for client certificates, and `DN` naming patterns which the NATS maintainers consider highly unlikely.</p>
<p>So this is an unlikely attack. Nonetheless, administrators who have been very sophisticated in their `DN` construction patterns might conceivably be impacted.</p>
<p>### Affected Versions</p>
<p>Fixed in nats-server 2.12.6 &amp; 2.11.15</p>
<p>### Workarounds</p>
<p>Developers should review their CA issuing practices.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3f24-pcvm-5jqc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33248</id>
    <title>UBUNTU-CVE-2026-33248</title>
    <updated>2026-10-03T08:06:34.412112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: nats-server, Ubuntu:25.10: nats-server, Ubuntu:Pro:26.04:LTS: nats-server</p>
<p>NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypass. This does require a valid certificate from a CA already trusted for client certificates, and `DN` naming patterns which the NATS maintainers consider highly unlikely. So this is an unlikely attack. Nonetheless, administrators who have been very sophisticated in their `DN` construction patterns might conceivably be impacted. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, developers should review their CA issuing practices.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33248"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0858</id>
    <title>WID-SEC-W-2026-0858 — NATS Server: Mehrere Schwachstellen</title>
    <updated>2026-10-03T08:06:34.412142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in NATS Server ausnutzen, um Informationen offenzulegen oder zu manipulieren, einen Denial-of-Service zu verursachen und Sicherheitsmechanismen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0858"/>
  </entry>
</feed>
