StackRadar

CVE-2026-33218

High

Advisory

Published 24 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
57
of 17,781 indexed, latest versions
Container images
53
deployed by those charts
Fix available
2 of 2
affected packages

NATS has pre-auth server panic via leafnode handling

Carried by container images the latest versions of 57 of 17,781 indexed charts deploy, on 53 images.

Affected packageAffected versionsFixed inImages
github.com/nats-io/nats-server/v2golangv0.0.0-20230518181934-4f2c9a51849d, v0.0.0-20230713200038-97dd7cb07a4f, v0.0.0-20231109212332-0883d32bbcc5, v0.0.0-20231206205519-fa8464d59b0a+36 more2.11.15, 2.12.652
natsbitnami2.11.8-02.11.151
OSV records
BIT-nats-2026-33218GHSA-vprv-35vv-q339
Also known as
GO-2026-4837

Charts affected

57 by stars
ChartLatestAffected imagesRadar Score
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-33218.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
github.com/nats-io/nats-server/v2@v2.9.19
2.11.15

Open the chart page →

1,970
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33218.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/nats-io/nats-server/v2@v2.1.4
2.11.15

Open the chart page →

3,764
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-33218.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
github.com/nats-io/nats-server/v2@v0.0.0-20250501093519-f91ddd892565
2.11.15

Open the chart page →

7,248
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2026-33218.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
github.com/nats-io/nats-server/v2@v2.7.4
2.11.15
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/nats-io/nats-server/v2@v2.7.4
2.11.15

Open the chart page →

4,815
tfy-distributortruefoundryVerified publisher0.0.12 of 4See more

tfy-distributor truefoundry 0.0.1

2 of the 4 container images this version deploys carry CVE-2026-33218.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
github.com/nats-io/nats-server/v2@v0.0.0-20231206205519-fa8464d59b0a
2.11.15
natsio/prometheus-nats-exporter:0.13.02adf791d9f9f
github.com/nats-io/nats-server/v2@v2.10.3
2.11.15

Open the chart page →

17,323
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-33218.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/nats-io/nats-server/v2@v2.11.0
2.11.15

Open the chart page →

45,239
nats-account-serverwenerme0.8.11 of 1See more

nats-account-server wenerme 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-33218.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
github.com/nats-io/nats-server/v2@v2.3.3
2.11.15

Open the chart page →

2,634

Container images carrying it

53 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
github.com/nats-io/nats-server/v2@v2.8.5-0.20220811224153-d8d25d9b0b1c
2.11.15
1
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
github.com/nats-io/nats-server/v2@v2.12.4
2.12.6
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/nats-io/nats-server/v2@v2.12.0
2.12.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.