CVE-2026-58251: NATS Server: Queue Subscribe Authz Bypass
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by using a queue subscription, because queue-specific deny evaluation could override the plain subject deny result when the queue name itself was not denied. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16.
Other sources
NATS Server: Queue Subscribe Authz Bypass
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.31.0-24 - Upgrade
Upgrade
nats-serverto a version that resolves this vulnerability.Fixed in 2.14.0 - Upgrade
Upgrade
nats-serverto a version that resolves this vulnerability.Fixed in 2.12.7 - Upgrade
Upgrade
nats-serverto a version that resolves this vulnerability.Fixed in 2.11.16
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58251?
CVE-2026-58251 has a medium severity rating of 6.5.
How do I fix CVE-2026-58251?
To fix CVE-2026-58251, upgrade to NATS Server version 2.14.0 or later, 2.12.7 or later, or 2.11.16 or later.
What type of vulnerability is CVE-2026-58251?
CVE-2026-58251 is an authorization bypass vulnerability related to queue subscriptions in NATS Server.
What impact does CVE-2026-58251 have?
CVE-2026-58251 allows authenticated users with subscription deny permissions to access resources they are typically not authorized to.
Which versions of NATS Server are affected by CVE-2026-58251?
NATS Server versions prior to 2.14.0, 2.12.7, and 2.11.16 are affected by CVE-2026-58251.