Description
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing configured subscribe permissions and exposing MQTT QoS2 protocol metadata for sessions in the account. This issue is fixed in versions 2.14.3 and 2.12.12.
Severity (CVSS)
| Base score | 4.3 |
|---|---|
| Severity | Medium |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| Provided by | CNA |
Weaknesses
- CWE-863 — CWE-863: Incorrect Authorization
Affected products
| Vendor | Product | Versions |
|---|---|---|
| nats-io | nats-server | < 2.12.12; >= 2.14.0-RC.1, < 2.14.3 |
References
- https://github.com/nats-io/nats-server/security/advisories/GHSA-4g68-3pwx-5vfj (x_refsource_CONFIRM)
- https://github.com/nats-io/nats-server/commit/297b166be60fe13144084eed4b25201ead03204a (x_refsource_MISC)
- https://github.com/nats-io/nats-server/commit/34b09657bb596d5f850eaa5cfc97ea6b2f989a97 (x_refsource_MISC)
- https://github.com/nats-io/nats-server/releases/tag/v2.12.12 (x_refsource_MISC)
- https://github.com/nats-io/nats-server/releases/tag/v2.14.3 (x_refsource_MISC)
Generated from the official CVE List on 09 Jul 2026 07:08 UTC.