These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability was found in NATS Server, a high-performance server for NATS.io. The issue allowed a leafnode operator to send trace events to subjects that would not otherwise be permitted, potentially preventing normal delivery or storage of affected messages. This was due to inconsistent application of message trace destination checks to messages arriving through leafnode connections. The issue has bee [truncated]
CVE-2026-58253 is an authentication bypass vulnerability in NATS Server. Prior to versions 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could also apply to route or leafnode listeners. This allowed an unauthenticated peer to bypass inter-server CONNECT authentication and operate with the privileges associated with that connectio [truncated]
CVE-2026-58251 is a medium-severity vulnerability in NATS Server, a high-performance server for NATS.io. An authenticated user with subscription deny permissions could bypass a plain subject deny rule by using a queue subscription. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16. The vulnerability allows an attacker to potentially access unauthorized subjects by exploiting the queue subscripti [truncated]
CVE-2026-58214 is a MEDIUM severity vulnerability in NATS Server, allowing an authenticated MQTT client to bypass subscribe permissions. This issue enables clients to access internal $MQTT.deliver.pubrel subject family, potentially exposing MQTT QoS2 protocol metadata for sessions in the account. The vulnerability is fixed in NATS Server versions 2.14.3 and 2.12.12. Users of affected versions should apply [truncated]
CVE-2026-58213 is a high-severity vulnerability in NATS Server, a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to versions 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode connections, corrupting the forwarded protocol stream and allowing injecti [truncated]
CVE-2026-58210 is a high-severity vulnerability in NATS Server, allowing an unauthenticated MQTT client to consume server memory by retaining large incomplete MQTT CONNECT packets before authentication completed. This issue is fixed in versions 2.14.3 and 2.12.12. Affected product deployments should be reviewed for exposure, and owners should plan for vendor-supported updates or mitigations. The vulnerabi [truncated]
CVE-2026-58209 is a vulnerability in NATS Server that allows MQTT retained message delivery and QoS1+ durable replay to deliver messages whose original topics matched a subscriber configured subscribe deny rule. This issue is fixed in versions 2.14.3 and 2.12.12. The vulnerability occurs because these delivery paths do not consistently recheck the concrete original topic before sending the MQTT PUBLISH to [truncated]
CVE-2026-33247 is a high-severity vulnerability in NATS-Server, a cloud and edge native messaging system. The vulnerability exposes static credentials for all clients provided via argv (the command-line) to any user who can see the monitoring port. The `/debug/vars` end-point contains an unredacted copy of argv. This issue affects NATS-Server versions prior to 2.11.15 and 2.12.6. To mitigate, configure cr [truncated]
CVE-2026-33218 is a high-severity vulnerability in NATS-Server, a cloud and edge native messaging system. A client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. Versions 2.11.15 and 2.12.6 of NATS-Server contain a fix for this vulnerability. As a workaround, di [truncated]
CVE-2026-33217 is a high-severity vulnerability in NATS-Server, a cloud and edge native messaging system. The vulnerability allows MQTT clients to bypass ACL checks for MQTT subjects when using ACLs on message subjects in the `$MQTT.> namespace. This issue was addressed in versions 2.11.15 and 2.12.6 of NATS-Server. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.1, indica [truncated]
CVE-2026-27889 is a high-severity vulnerability in NATS-Server, a cloud and edge native messaging system. The vulnerability allows for a server panic due to a missing sanity check on a WebSockets frame. This issue was introduced in version 2.2.0 and affects versions prior to 2.11.14 and 2.12.5. The vulnerability is exploitable before authentication and is exposed to anyone who can connect to the WebSocket [truncated]