Intel

AIKIDO-2025-10224

github.com/nats-io/nats-server/v2 is vulnerable to Authentication Bypass

Authentication BypassCVE-2025-30215

90

Critical Risk

This Affects:

GOgithub.com/nats-io/nats-server/v2
2.2.0 - 2.10.26
Fixed in 2.10.27
2.11.0 - 2.11.0
Fixed in 2.11.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a critical issue tracked as CVE-2025-30215. This patch resolves the vulnerability by correctly validating the calling account on various system API calls and enforcing system and account limits during JetStream stream restore operations.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/nats-io/nats-server/v2 is vulnerable to Authentication Bypass in versions 2.2.0 - 2.10.26 and 2.11.0 - 2.11.0.

How to fix this

Upgrade the github.com/nats-io/nats-server/v2 library to the patch version.