8.8

CVE-2026-58253

NATS Server: Route API Auth Bypass

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could also apply to route or leafnode listeners, allowing an unauthenticated peer to bypass inter-server CONNECT authentication and operate with the privileges associated with that connection type. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxfoundationNats-server Version < 2.11.16
LinuxfoundationNats-server Version >= 2.12.0 < 2.12.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.134
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.8 2.8 5.3
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://github.com/nats-io/nats-server/releases/tag/v2.11.16
Release Notes
https://github.com/nats-io/nats-server/releases/tag/v2.12.7
Release Notes
https://github.com/nats-io/nats-server/releases/tag/v2.14.0
Release Notes
https://github.com/nats-io/nats-server/commit/7b81dd455ea95960090a84858c7662827948d1b6
Patch
https://github.com/nats-io/nats-server/commit/8b8e1ad4ceed32321e00d4fc6e76be05bc13bca6
Patch
https://github.com/nats-io/nats-server/commit/b86147e81710a52b72a7f7275f91d69f723f5cb3
Patch
https://github.com/nats-io/nats-server/security/advisories/GHSA-38x3-76xf-cq45
Vendor Advisory