Medium severity6.5NVD Advisory· Published Jul 8, 2026· Updated Jul 13, 2026
CVE-2026-58251
CVE-2026-58251
Description
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by using a queue subscription, because queue-specific deny evaluation could override the plain subject deny result when the queue name itself was not denied. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16.
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/nats-io/nats-server/commit/013586288078def45a6788096924eb4d150db65cnvdPatch
- github.com/nats-io/nats-server/commit/79c2f6e9ff87f594596337b6427dda85c38d1fe1nvdPatch
- github.com/nats-io/nats-server/commit/b9ffb63b85e7db3d25a13b2e234f5f7f7c13164dnvdPatch
- github.com/nats-io/nats-server/security/advisories/GHSA-jx8g-9g95-6322nvdVendor Advisory
- github.com/nats-io/nats-server/releases/tag/v2.11.16nvdRelease Notes
- github.com/nats-io/nats-server/releases/tag/v2.12.7nvdRelease Notes
- github.com/nats-io/nats-server/releases/tag/v2.14.0nvdRelease Notes
News mentions
0No linked articles in our index yet.