VDB
GO-2023-2133
GO-2023-2133
PUBLISHED
Authorization bypass in github.com/nats-io/nats-server/v2
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| wolfi | nats | 0 |
| chainguard | nats | 0 |
| github.com | nats-io/nats-server/v2 | 2.2.0, 2.10.0, 2.2.0 |
Timeline
- Oct 24, 2023 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://advisories.nats.io/CVE/secnote-2023-01.txt advisory
- https://github.com/nats-io/nats-server/discussions/4535 report
- https://github.com/nats-io/nats-server/pull/4605 fix
- https://github.com/nats-io/nats-server/commit/fa5b7afcb64e7e887e49afdd032358802b5c4478 fix
- https://github.com/nats-io/nats-server/releases/tag/v2.10.2 fix
- https://github.com/nats-io/nats-server/releases/tag/v2.9.23 fix