← Back

CVE-2026-58209

nvd nist
Published: Jul 8, 2026Modified: Jul 13, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: security-advisories@github.com (Secondary)

Description

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not consistently recheck the concrete original topic before sending the MQTT PUBLISH to the subscriber. This issue is fixed in versions 2.14.3 and 2.12.12.

Affected (2)

Nats Server
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Linuxfoundation
Before 2.12.12
From 2.14.0 to 2.14.3

References (5)

Timeline

No history available yet.