<Vulnerability name="CVE-2026-58251">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-08T19:40:28</PublicDate>
    <Bugzilla id="2498195" url="https://bugzilla.redhat.com/show_bug.cgi?id=2498195" xml:lang="en:us">
github.com/nats-io/nats-server: NATS Server: Information disclosure due to bypass of subject deny rules via queue subscriptions
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-551</CWE>
    <Details xml:lang="en:us" source="Mitre">
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by using a queue subscription, because queue-specific deny evaluation could override the plain subject deny result when the queue name itself was not denied. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in NATS Server, a high-performance messaging system. An authenticated user with specific permissions could bypass security rules designed to deny access to certain message subjects. This bypass occurs when a queue subscription is used, allowing the user to access information that should otherwise be restricted. The consequence is unauthorized information disclosure, potentially exposing sensitive data.
    </Details>
    <Statement xml:lang="en:us">
Moderate: An information disclosure flaw was found in NATS Server where an authenticated user with subscription deny permissions could bypass subject deny rules using a queue subscription. This could lead to unauthorized access to sensitive data.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>nats-server2.12</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>nats-server2.14</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-58251
https://nvd.nist.gov/vuln/detail/CVE-2026-58251
https://github.com/nats-io/nats-server/commit/013586288078def45a6788096924eb4d150db65c
https://github.com/nats-io/nats-server/commit/79c2f6e9ff87f594596337b6427dda85c38d1fe1
https://github.com/nats-io/nats-server/commit/b9ffb63b85e7db3d25a13b2e234f5f7f7c13164d
https://github.com/nats-io/nats-server/releases/tag/v2.11.16
https://github.com/nats-io/nats-server/releases/tag/v2.12.7
https://github.com/nats-io/nats-server/releases/tag/v2.14.0
https://github.com/nats-io/nats-server/security/advisories/GHSA-jx8g-9g95-6322
    </References>
</Vulnerability>