CVE-2020-26892

CRITICAL9.8EPSS 0.55%

Incorrect handling of credential expiry in github.com/nats-io/jwt

Published: 5/21/2021Modified: 4/28/2026

Description

The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (13)