CVE-2026-58254

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were applied to ordinary client connections but not consistently to messages arriving through leafnode connections, allowing a leafnode operator to send trace events to subjects that would not otherwise be permitted and to use trace-only behavior to prevent normal delivery or storage of affected messages. This issue is fixed in versions 2.14.3 and 2.12.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*

History

13 Jul 2026, 15:28

Type Values Removed Values Added
References () https://github.com/nats-io/nats-server/commit/cbe845932980b71563efac5cfa4cc751c88936cd - () https://github.com/nats-io/nats-server/commit/cbe845932980b71563efac5cfa4cc751c88936cd - Patch
References () https://github.com/nats-io/nats-server/releases/tag/v2.12.8 - () https://github.com/nats-io/nats-server/releases/tag/v2.12.8 - Release Notes
References () https://github.com/nats-io/nats-server/releases/tag/v2.14.3 - () https://github.com/nats-io/nats-server/releases/tag/v2.14.3 - Release Notes
References () https://github.com/nats-io/nats-server/security/advisories/GHSA-p3j5-5hrq-p75h - () https://github.com/nats-io/nats-server/security/advisories/GHSA-p3j5-5hrq-p75h - Vendor Advisory
First Time Linuxfoundation nats-server
Linuxfoundation
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*

08 Jul 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 20:16

Updated : 2026-07-13 15:28


NVD link : CVE-2026-58254

Mitre link : CVE-2026-58254

CVE.ORG link : CVE-2026-58254


JSON object : View

Products Affected

linuxfoundation

  • nats-server
CWE
CWE-863

Incorrect Authorization