NatJack: A New Attack Class Exploiting Trust in Network Address Translation
NatJack manipulates long-standing assumptions in how network address translation tables operate. The techniques can enable attackers to hijack TCP connections, poison DNS responses, identify connection ports and disrupt connectivity across affected NAT implementations.
Read the Synack Security Research Report for technical analysis, affected infrastructure, detection signals and practical mitigation guidance.
2 CVEs Assigned
Two CVEs have been assigned to date.
CVSS 7.2 to 9.6
Scores range from High to Critical.
Multiple NAT Implementations
Tested across independently developed implementations.
Presented at Black Hat
Full technical research presented by Malcolm Stagg.
A Legacy Trust Assumption Meets Modern Infrastructure
Network address translation was created to address the shortage of IPv4 addresses. Its design assumed that devices sharing the same NAT table could trust one another.
Modern cloud, container and virtualized environments have changed that trust model.
NatJack is a newly identified class of attacks that manipulates NAT table behavior. Independent testing found that all evaluated NAT implementations were vulnerable to one or more NatJack techniques, despite using different operating systems and independently developed codebases.
The issue is not limited to a single coding error or vendor implementation. It arises from shared assumptions about sequencing, port allocation and trust between devices using the same NAT table.
What NatJack Can Enable
Hijack TCP Connections
Take control of an active TCP connection passing through an affected NAT implementation.
Poison DNS Responses
Intercept and maliciously alter UDP DNS responses.
Identify Connection Ports
Determine the port assigned by a NAT device to another active connection.
Force Denial of Service
Exhaust the NAT table and disrupt network connectivity.
More Than a Router Vulnerability
NatJack affects the behavior of physical and virtual infrastructure that performs network address translation.
Vulnerable does not always mean immediately at risk. The practical risk depends on whether an untrusted or privileged workload can share NAT infrastructure with trusted systems.
Organizations should prioritize environments in which trusted and untrusted workloads operate behind the same NAT table or internet gateway.
Design-Level Vulnerabilities Require Human Creativity
Conventional vulnerability scanning typically searches for known software versions, signatures, misconfigurations and documented CVEs.
NatJack emerged through manual adversarial testing of how NAT devices behave under unusual network conditions. The research followed an unexpected response-sequencing anomaly through router firmware to the underlying connection-tracking behavior.
The same type of design assumption was then identified across independently developed implementations.
This research demonstrates why security testing must examine not only known software flaws, but also the assumptions on which systems and protocols were built.
Design-level flaws surface when researchers challenge the assumptions a system was built on.
How Organizations Can Reduce Exposure
No single vendor patch addresses the complete attack class across every NAT implementation. Available updates may increase the complexity of exploitation, while broader remediation will require changes across multiple vendors and infrastructure categories.
The report provides more detailed detection signals and mitigation recommendations for cloud, container, Kubernetes, router and firewall environments.
View Detection and Mitigation Guidance
Malcolm Stagg
Independent Researcher, SODIUM-24
Synack Red Team Researcher
Malcolm Stagg discovered NatJack through manual adversarial testing that challenged long-standing assumptions in network address translation. He is an independent security researcher with SODIUM-24 and a member of the Synack Red Team.
Malcolm presented the full technical research at Black Hat USA 2026 in Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure.
Read the NatJack Security Research Report
Explore the technical foundations of NatJack, the four attack techniques, affected infrastructure, assigned CVEs, potential detection signals and mitigation guidance.
No form required.
NatJack Security Research FAQ
What is NatJack? +
NatJack is a newly identified class of attacks that manipulates the behavior of network address translation tables. Depending on the implementation and environment, the techniques may enable connection hijacking, DNS response poisoning, connection-port identification or denial of service.
Is every router at immediate risk? +
No. A NAT implementation may exhibit vulnerable behavior without every environment presenting the same practical risk. Exposure depends on network architecture, workload privileges and whether untrusted systems share NAT infrastructure with trusted systems.
Does NatJack affect cloud and container environments? +
The research identified relevant exposure in virtual bridges, hypervisors, containers and cloud environments that perform or depend on NAT.
Is there a complete fix? +
Not yet. Some vendor updates increase attack complexity or reduce the practicality of certain techniques, but broader remediation will require an incremental, multi-vendor effort.
How can organizations reduce their risk? +
Organizations should encrypt traffic, separate workloads by trust level, reduce unnecessary privileges, avoid shared NAT infrastructure between trusted and untrusted systems and apply relevant vendor updates.
AI Finds More.
Humans Prove What Matters.
Continuous Pentesting at Scale
Synack combines Sara AI Pentesting, the Synack Red Team and the Synack Platform to expand testing coverage, prove real-world exploitability and turn trusted findings into action.
Explore the Synack PlatformNo video selected
Select a video type in the sidebar.
Watch Tom Wayne and Tim Nordvedt from Synack walk through Sara AI Pentesting — and how to bring it to your customers before the market catches up.
- Unlock new deals with a differentiated AI entry point
- Stand out with AI-powered coverage and human-validated findings
- Get the playbook, messaging, and tools to sell faster