Junglewise Threat Intelligence

CVE-2026-58213: NATS Server protocol injection via MQTT subscription filters

CVE-2026-58213 · Severity: high · CVSS 7.1 · Published 2026-07-08

Technologies: Nats-Io NATS Server.

Executive brief

NATS Server is a high-performance messaging system used for cloud and edge computing. A vulnerability in how the server handles MQTT client requests could allow a user to send specially crafted messages that disrupt the internal communication between servers. This could lead to unauthorized protocol operations or data stream corruption, potentially impacting the integrity and confidentiality of the messaging network.

Technical details

NATS Server is vulnerable to a protocol injection flaw (CWE-74) when handling MQTT subscription filters. An authenticated MQTT client can include protocol control characters in subscription filters or publication subjects. When the server forwards this data to route or leafnode connections, it fails to properly neutralize these characters, leading to the corruption of the NATS protocol stream. This allows an attacker to inject unintended NATS protocol operations into the downstream connection. The issue is resolved in NATS Server versions 2.14.1 and 2.12.9 by ensuring invalid subject characters are rejected during the MQTT ingress process.

Affected products

  • nats-io NATS Server < 2.12.9, >= 2.14.0-RC.1, < 2.14.1

Timeline

  • 2026-07-08: advisory: NVD publication date
  • 2026-05-20: patched: Release of versions 2.12.9 and 2.14.1

References