Impact
NATS Server versions earlier than 2.14.0, 2.12.7, and 2.11.16 contain a flaw that permits a non‑authenticated peer to connect as a route or leafnode when the no_auth_user configuration is enabled. The server incorrectly applies a client‑connection parsing path to inter‑server listeners, causing the CONNECT authentication step to be skipped and allowing the peer to operate with the privileges of a route or leafnode. This bypass effectively grants an attacker the ability to join the NATS cluster, subscribe to, and publish messages, and potentially intercept or alter traffic that should be restricted to authenticated peers.
Affected Systems
Any deployment of NATS Server from the nats‑io organization using versions before 2.14.0, before 2.12.7, or before 2.11.16 that has the no_auth_user setting enabled on inter‑server route or leafnode listeners is vulnerable. The affected product is the NATS Server component of the NATS.io cloud‑and‑edge‑native messaging system.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity, while the EPSS score of less than 1 % implies a low probability of exploitation at the present time. It is not listed in the CISA KEV catalog. The attack vector is remote network access to a route or leafnode listening port; the flaw bypasses inter‑server authentication, allowing an attacker to join the cluster without credentials and to operate with route or leafnode privileges. Though exploitation may be uncommon, the potential impact on confidentiality, integrity, and availability of cluster messaging is significant until the affected software is upgraded or otherwise secured.
OpenCVE Enrichment