CVE-2026-58254
CVE-2026-58254 is a NATS Server authorization flaw in message tracing across leaf-node connections; affected operators should use the vendor-fixed 2.12.12 or 2.14.3 release for their branch.
These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-58254 is a NATS Server authorization flaw in message tracing across leaf-node connections; affected operators should use the vendor-fixed 2.12.12 or 2.14.3 release for their branch.
CVE-2026-58253 is an authentication bypass vulnerability in NATS Server. Prior to versions 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could also apply to route or leafnode listeners. This allowed an unauthenticated peer to bypass inter-server CONNECT authentication and operate with the privileges associated with that connectio [truncated]
CVE-2026-58251 is a medium-severity vulnerability in NATS Server, a high-performance server for NATS.io. An authenticated user with subscription deny permissions could bypass a plain subject deny rule by using a queue subscription. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16. The vulnerability allows an attacker to potentially access unauthorized subjects by exploiting the queue subscripti [truncated]
CVE-2026-58214 is a MEDIUM severity vulnerability in NATS Server, allowing an authenticated MQTT client to bypass subscribe permissions. This issue enables clients to access internal $MQTT.deliver.pubrel subject family, potentially exposing MQTT QoS2 protocol metadata for sessions in the account. The vulnerability is fixed in NATS Server versions 2.14.3 and 2.12.12. Users of affected versions should apply [truncated]
CVE-2026-58213 is a high-severity vulnerability in NATS Server, a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to versions 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode connections, corrupting the forwarded protocol stream and allowing injecti [truncated]
CVE-2026-58210 is a high-severity vulnerability in NATS Server, allowing an unauthenticated MQTT client to consume server memory by retaining large incomplete MQTT CONNECT packets before authentication completed. This issue is fixed in versions 2.14.3 and 2.12.12. Affected product deployments should be reviewed for exposure, and owners should plan for vendor-supported updates or mitigations. The vulnerabi [truncated]
CVE-2026-58209 is a vulnerability in NATS Server that allows MQTT retained message delivery and QoS1+ durable replay to deliver messages whose original topics matched a subscriber configured subscribe deny rule. This issue is fixed in versions 2.14.3 and 2.12.12. The vulnerability occurs because these delivery paths do not consistently recheck the concrete original topic before sending the MQTT PUBLISH to [truncated]
CVE-2026-33247 debrief based on the supplied source corpus. The CVE record was published on 2026-03-25T20:16:33.223Z and has not been modified since then. The NVD entry is currently Modified. This high-severity vulnerability in NATS server exposes static credentials provided via command-line arguments to users with access to the monitoring port. Defenders responsible for NATS server deployments, especiall [truncated]
A High-Performance server for NATS.io, a cloud and edge native messaging system, is vulnerable to a denial-of-service (DoS) attack. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. This vulnerability can lead to service disruptions, emphasizing the need for prompt patching or mitigation. Def [truncated]
CVE-2026-33217 is a high-severity vulnerability in NATS-Server, a cloud and edge native messaging system. The vulnerability allows MQTT clients to bypass ACL checks for MQTT subjects when using ACLs on message subjects in the `$MQTT.> namespace. This issue was addressed in versions 2.11.15 and 2.12.6 of NATS-Server. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.1, indica [truncated]
A High-Performance server for NATS.io, a cloud and edge native messaging system, is vulnerable to a server panic triggered by a missing sanity check on a WebSockets frame. This issue affects versions starting from 2.2.0 and prior to 2.11.14 and 2.12.5. The vulnerability is exposed to anyone who can connect to the WebSockets port before authentication. Deployments using WebSockets and exposing the network [truncated]