HIGH🇬🇧 English

CVE-2023-46129

CVSS 7.5v3.1pub. 2023-10-31upd. 2026-03-30

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library's `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing. FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Linuxfoundation Nats Server

    APP
    Linuxfoundation
    2.10.0 – 2.10.4 (bez)
  • Nats Nkeys

    APP
    Nats
    0.4.0 – 0.4.6 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2022-28357CRITICAL9.8PL ✓ten sam produkt

Path traversal w NATS nats-server umożliwiający nieautoryzowane działania zarządzania

CVE-2020-26892CRITICAL9.8PL ✓ten sam produkt

Nieprawidłowa kontrola dostępu w JWT library w NATS nats-server

CVE-2026-58207HIGH7.7PL ✓ten sam produkt

NATS Server: przepełnienie arytmetyczne w paginacji Connz prowadzi do crash serwera

CVE-2026-58210HIGH7.5PL ✓ten sam produkt

NATS Server: wyczerpanie pamięci przez niekompletne pakiety MQTT CONNECT

CVE-2026-58213HIGH7.1PL ✓ten sam produkt

NATS Server: injection protokołu przez filtry subskrypcji MQTT