CVE detail
CVE-2026-33247
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any user who can see the monitoring port, if that too is enabled. The `/debug/vars` end-point contains an unredacted copy of argv. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, configure credentials inside a configuration file instead of via argv, and do not enable the monitoring port if using secrets in argv. Best practice remains to not expose the monitoring port to the Internet, or to untrusted network sources.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33247.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 25, 2026, 8:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2451486bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 25, 2026, 8:16 PM - https://access.redhat.com/security/cve/CVE-2026-33247access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 25, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:23345access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 25, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:22347access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 25, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:21769access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 25, 2026, 8:16 PM No excerpt available.
Exploitgithub.comMar 25, 2026, 8:16 PM- https://advisories.nats.io/CVE/secnote-2026-14.txtadvisories.nats.io
No excerpt available.
Vendor Advisoryadvisories.nats.ioMar 25, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-12139CVSS 4.4 · Medium
Tanium addressed an information disclosure vulnerability in Connect.
- CVE-2026-9494CVSS 5.5 · Medium
An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/…
- CVE-2026-44934CVSS 7.0 · High
A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles,…
- CVE-2026-12250CVSS 7.9 · High
Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavation. This is…
- CVE-2026-41357CVSS 2.0 · Low
OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized process.env to child processes. Attackers can…
- CVE-2026-40173CVSS 9.4 · Critical
Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endp…