CVE-2026-58213
Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode connections, corrupting the forwarded protocol stream and allowing…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode connections, corrupting the forwarded protocol stream and allowing injection of unintended NATS protocol operations. This issue is fixed in versions 2.14.1 and 2.12.9.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- linuxfoundation/nats-server
- Source
- security-advisories@github.com
References
- https://github.com/nats-io/nats-server/commit/366837cfc65ab9ccb4f98193c65e8daf238582d8Patch
- https://github.com/nats-io/nats-server/commit/64ebae40051ee497c481e10f316238faf0de1736Patch
- https://github.com/nats-io/nats-server/commit/f14856b9e57a36818f43851cb69b6e33670885c9Patch
- https://github.com/nats-io/nats-server/pull/8163Issue Tracking, Patch
- https://github.com/nats-io/nats-server/pull/8164Issue Tracking, Patch
- https://github.com/nats-io/nats-server/releases/tag/v2.12.9Release Notes
- https://github.com/nats-io/nats-server/releases/tag/v2.14.1Release Notes
- https://github.com/nats-io/nats-server/security/advisories/GHSA-qrcv-3558-gj4fVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.