CVE-2025-30215 | NATS.io up to 2.10.26/2.11.0 JetStream Asset access control
A vulnerability classified as critical was found in NATS.io up to 2.10.26/2.11.0. Affected by this vulnerability is an unknown functionality of the component JetStream Asset Handler. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2025-30215. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.