6.5
CVE-2026-58251
- EPSS 0.34%
- Veröffentlicht 08.07.2026 19:40:28
- Zuletzt bearbeitet 13.07.2026 15:23:31
- CVE-Watchlists
- Unerledigt
NATS Server: Queue Subscribe Authz Bypass
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by using a queue subscription, because queue-specific deny evaluation could override the plain subject deny result when the queue name itself was not denied. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linuxfoundation ≫ Nats-server Version < 2.11.16
Linuxfoundation ≫ Nats-server Version >= 2.12.0 < 2.12.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.264 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/nats-io/nats-server/security/advisories/GHSA-jx8g-9g95-6322
https://github.com/nats-io/nats-server/commit/013586288078def45a6788096924eb4d150db65c
https://github.com/nats-io/nats-server/commit/79c2f6e9ff87f594596337b6427dda85c38d1fe1
https://github.com/nats-io/nats-server/commit/b9ffb63b85e7db3d25a13b2e234f5f7f7c13164d
https://github.com/nats-io/nats-server/releases/tag/v2.11.16
https://github.com/nats-io/nats-server/releases/tag/v2.12.7
https://github.com/nats-io/nats-server/releases/tag/v2.14.0