While working in perforator project, I found that the application uses github.com/nats-io/nats-server/v2, which is affected by an mTLS authentication bypass vulnerability. The issue occurs in the verify_and_map feature, where incorrect matching of Subject DN (Distinguished Name) patterns can allow authentication bypass under certain certificate configurations.
CVE Report
CVE link