CVE-2026-58253: NATS Server: Route API Auth Bypass
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when noauthuser was configured, a parser fast path intended for ordinary client connections could also apply to route or leafnode listeners, allowing an unauthenticated peer to bypass inter-server CONNECT authentication and operate with the privileges associated with that connection type. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.31.0-24 - Upgrade
Upgrade
nats-serverto a version that resolves this vulnerability.Fixed in 2.14.0 - Upgrade
Upgrade
nats-serverto a version that resolves this vulnerability.Fixed in 2.12.7 - Upgrade
Upgrade
nats-serverto a version that resolves this vulnerability.Fixed in 2.11.16
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58253?
CVE-2026-58253 has a high severity rating of 8.8.
What is the impact of CVE-2026-58253?
CVE-2026-58253 allows an unauthenticated user to bypass authentication for the Route API on NATS Server.
How do I fix CVE-2026-58253?
To fix CVE-2026-58253, upgrade to NATS Server version 2.14.0 or later, 2.12.7 or later, or 2.11.16 or later.
What configurations are affected by CVE-2026-58253?
CVE-2026-58253 is affected when the no_auth_user is configured for various listeners on NATS Server.
Who is impacted by CVE-2026-58253?
Users running affected versions of NATS Server on Linux systems without proper configurations are impacted by CVE-2026-58253.