CVE-2026-58209

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not consistently recheck the concrete original topic before sending the MQTT PUBLISH to the subscriber. This issue is fixed in versions 2.14.3 and 2.12.12.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*

History

13 Jul 2026, 14:15

Type Values Removed Values Added
References () https://github.com/nats-io/nats-server/releases/tag/v2.12.12 - Release Notes, Product () https://github.com/nats-io/nats-server/releases/tag/v2.12.12 - Release Notes
References () https://github.com/nats-io/nats-server/releases/tag/v2.14.3 - Release Notes, Product () https://github.com/nats-io/nats-server/releases/tag/v2.14.3 - Release Notes

13 Jul 2026, 13:53

Type Values Removed Values Added
References () https://github.com/nats-io/nats-server/commit/181b1f51f40b9954c57e9d478e051fb257679356 - () https://github.com/nats-io/nats-server/commit/181b1f51f40b9954c57e9d478e051fb257679356 - Patch
References () https://github.com/nats-io/nats-server/commit/1c429b6fdc5afd4188cc5faf1127f6334896cd87 - () https://github.com/nats-io/nats-server/commit/1c429b6fdc5afd4188cc5faf1127f6334896cd87 - Patch
References () https://github.com/nats-io/nats-server/releases/tag/v2.12.12 - () https://github.com/nats-io/nats-server/releases/tag/v2.12.12 - Release Notes, Product
References () https://github.com/nats-io/nats-server/releases/tag/v2.14.3 - () https://github.com/nats-io/nats-server/releases/tag/v2.14.3 - Release Notes, Product
References () https://github.com/nats-io/nats-server/security/advisories/GHSA-7qmq-8cc4-hxwg - () https://github.com/nats-io/nats-server/security/advisories/GHSA-7qmq-8cc4-hxwg - Vendor Advisory
CPE cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
First Time Linuxfoundation nats-server
Linuxfoundation

08 Jul 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 20:16

Updated : 2026-07-13 14:15


NVD link : CVE-2026-58209

Mitre link : CVE-2026-58209

CVE.ORG link : CVE-2026-58209


JSON object : View

Products Affected

linuxfoundation

  • nats-server
CWE
CWE-863

Incorrect Authorization