Unknown · Nats Server · CVE-2026-58252
**Name of the Vulnerable Software and Affected Versions**
NATS Server versions prior to 2.14.0
NATS Server versions prior to 2.12.7
NATS Server versions prior to 2.11.16
**Description**
An authenticated user can receive messages on denied subjects. This occurs when a wildcard subscription overlaps with a configured wildcard deny rule without being a subset of it. Additionally, queue subscriptions may interfere with message delivery to legitimate queue consumers.
**Recommendations**
Update to version 2.14.0
Update to version 2.12.7
Update to version 2.11.16