PT-2026-56564 · Unknown · Nats Server
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NATS Server versions prior to 2.14.0
NATS Server versions prior to 2.12.7
NATS Server versions prior to 2.11.16
Description
An authenticated user can receive messages on denied subjects. This occurs when a wildcard subscription overlaps with a configured wildcard deny rule without being a subset of it. Additionally, queue subscriptions may interfere with message delivery to legitimate queue consumers.
Recommendations
Update to version 2.14.0
Update to version 2.12.7
Update to version 2.11.16
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nats Server