CVE-2026-58209 Details
Description
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not consistently recheck the concrete original topic before sending the MQTT PUBLISH to the subscriber. This issue is fixed in versions 2.14.3 and 2.12.12.
A vulnerability in NATS Server's MQTT implementation prior to versions 2.14.3 and 2.12.12 allows retained message delivery and QoS1+ durable replay to bypass subscriber deny rules. This occurs because the delivery paths for retained messages and QoS1+ replays do not consistently verify the original topic before sending the message to the subscriber. As a result, messages from denied topics can still be delivered if the subscriber has broad wildcard permissions that overlap with the denied subjects.
Upgrade to NATS Server versions 2.14.3 or 2.12.12.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation nats-server | < 2.12.12 >= 2.14.0, < 2.14.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | Reanalysis | [email protected] |
| Jul 13, 2026 | Initial Analysis | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |