Extend SECTION SETTINGS - THIS ELEMENT WILL BE SHOWN ONLY IN THE CONTENT EDITOR
Synack Security Research

NatJack: A New Attack Class Exploiting Trust in Network Address Translation

NatJack manipulates long-standing assumptions in how network address translation tables operate. The techniques can enable attackers to hijack TCP connections, poison DNS responses, identify connection ports and disrupt connectivity across affected NAT implementations.

Read the Synack Security Research Report for technical analysis, affected infrastructure, detection signals and practical mitigation guidance.

Coordinated Disclosure

2 CVEs Assigned

Two CVEs have been assigned to date.

Severity Range

CVSS 7.2 to 9.6

Scores range from High to Critical.

Independent Testing

Multiple NAT Implementations

Tested across independently developed implementations.

Black Hat USA 2026

Presented at Black Hat

Full technical research presented by Malcolm Stagg.

The Research

A Legacy Trust Assumption Meets Modern Infrastructure

Network address translation was created to address the shortage of IPv4 addresses. Its design assumed that devices sharing the same NAT table could trust one another.

Modern cloud, container and virtualized environments have changed that trust model.

NatJack is a newly identified class of attacks that manipulates NAT table behavior. Independent testing found that all evaluated NAT implementations were vulnerable to one or more NatJack techniques, despite using different operating systems and independently developed codebases.

The issue is not limited to a single coding error or vendor implementation. It arises from shared assumptions about sequencing, port allocation and trust between devices using the same NAT table.

Attack Techniques

What NatJack Can Enable

Hijack TCP Connections

Take control of an active TCP connection passing through an affected NAT implementation.

Poison DNS Responses

Intercept and maliciously alter UDP DNS responses.

Identify Connection Ports

Determine the port assigned by a NAT device to another active connection.

Force Denial of Service

Exhaust the NAT table and disrupt network connectivity.

Scope and Impact

More Than a Router Vulnerability

NatJack affects the behavior of physical and virtual infrastructure that performs network address translation.

Routers and firewalls
Docker and Kubernetes environments
Hypervisors, including Hyper-V
Cloud NAT gateways
Virtual bridges and switches
Public cloud container and virtualization services

Vulnerable does not always mean immediately at risk. The practical risk depends on whether an untrusted or privileged workload can share NAT infrastructure with trusted systems.

Organizations should prioritize environments in which trusted and untrusted workloads operate behind the same NAT table or internet gateway.

Why It Matters

Design-Level Vulnerabilities Require Human Creativity

Conventional vulnerability scanning typically searches for known software versions, signatures, misconfigurations and documented CVEs.

NatJack emerged through manual adversarial testing of how NAT devices behave under unusual network conditions. The research followed an unexpected response-sequencing anomaly through router firmware to the underlying connection-tracking behavior.

The same type of design assumption was then identified across independently developed implementations.

This research demonstrates why security testing must examine not only known software flaws, but also the assumptions on which systems and protocols were built.

Design-level flaws surface when researchers challenge the assumptions a system was built on.

Detection and Mitigation

How Organizations Can Reduce Exposure

No single vendor patch addresses the complete attack class across every NAT implementation. Available updates may increase the complexity of exploitation, while broader remediation will require changes across multiple vendors and infrastructure categories.

Encrypt trafficEncrypt internal and external traffic using TLS.
Protect DNSUse DNSSEC and encrypted DNS.
Separate workloadsSeparate trusted and untrusted containers, virtual machines and workloads.
Avoid shared NATAvoid shared NAT infrastructure for workloads with different trust levels.
Segment networksEnable IP source protections and network segmentation.
Restrict privilegesRestrict unnecessary privileges and network capabilities.
Monitor NAT behaviorMonitor for unusual NAT-table utilization and anomalous packet activity.

The report provides more detailed detection signals and mitigation recommendations for cloud, container, Kubernetes, router and firewall environments.

View Detection and Mitigation Guidance
Malcolm Stagg, independent security researcher and Synack Red Team member
About the Researcher

Malcolm Stagg

Independent Researcher, SODIUM-24
Synack Red Team Researcher

Malcolm Stagg discovered NatJack through manual adversarial testing that challenged long-standing assumptions in network address translation. He is an independent security researcher with SODIUM-24 and a member of the Synack Red Team.

Malcolm presented the full technical research at Black Hat USA 2026 in Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure.

Synack Security Research Report

Read the NatJack Security Research Report

Explore the technical foundations of NatJack, the four attack techniques, affected infrastructure, assigned CVEs, potential detection signals and mitigation guidance.

No form required.

Frequently Asked Questions

NatJack Security Research FAQ

What is NatJack?

NatJack is a newly identified class of attacks that manipulates the behavior of network address translation tables. Depending on the implementation and environment, the techniques may enable connection hijacking, DNS response poisoning, connection-port identification or denial of service.

Is every router at immediate risk?

No. A NAT implementation may exhibit vulnerable behavior without every environment presenting the same practical risk. Exposure depends on network architecture, workload privileges and whether untrusted systems share NAT infrastructure with trusted systems.

Does NatJack affect cloud and container environments?

The research identified relevant exposure in virtual bridges, hypervisors, containers and cloud environments that perform or depend on NAT.

Is there a complete fix?

Not yet. Some vendor updates increase attack complexity or reduce the practicality of certain techniques, but broader remediation will require an incremental, multi-vendor effort.

How can organizations reduce their risk?

Organizations should encrypt traffic, separate workloads by trust level, reduce unnecessary privileges, avoid shared NAT infrastructure between trusted and untrusted systems and apply relevant vendor updates.

Synack

AI Finds More.

Humans Prove What Matters.

Continuous Pentesting at Scale

Synack combines Sara AI Pentesting, the Synack Red Team and the Synack Platform to expand testing coverage, prove real-world exploitability and turn trusted findings into action.

Explore the Synack Platform
Extend SECTION SETTINGS - THIS ELEMENT WILL BE SHOWN ONLY IN THE CONTENT EDITOR

No video selected

Select a video type in the sidebar.

 

Watch Tom Wayne and Tim Nordvedt from Synack walk through Sara AI Pentesting — and how to bring it to your customers before the market catches up.

  • Unlock new deals with a differentiated AI entry point
  • Stand out with AI-powered coverage and human-validated findings
  • Get the playbook, messaging, and tools to sell faster
Ready to take Sara AI Pentesting to your customers?