Executive brief
NATS Server is a high-performance messaging system used for cloud and edge computing. A security flaw allowed authenticated users to bypass access controls and subscribe to restricted data channels by using a specific 'queue subscription' method. This could lead to unauthorized access to sensitive information that the user was explicitly forbidden from viewing.
Technical details
An improper authorization vulnerability (CWE-285) exists in NATS Server's ACL evaluation logic. When a user creates a queue subscription, the server's check for queue-specific deny rules could incorrectly override a previously matched 'deny' rule for the plain subject. Specifically, if a subject was denied but the queue name itself was not explicitly denied, the subscription was permitted. This allows an authenticated attacker with network access to bypass 'subscribe deny' permissions. The issue is resolved in versions 2.11.16, 2.12.7, and 2.14.0 by ensuring queue-specific checks do not overwrite existing subject-based denials.
Affected products
- nats-io NATS Server < 2.11.16, >= 2.12.0-RC.1 < 2.12.7, < 2.14.0
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
- 2026-04-14: patched: Fixes included in v2.11.16 and v2.12.7 releases
References
- https://github.com/nats-io/nats-server/commit/013586288078def45a6788096924eb4d150db65c
- https://github.com/nats-io/nats-server/commit/79c2f6e9ff87f594596337b6427dda85c38d1fe1
- https://github.com/nats-io/nats-server/commit/b9ffb63b85e7db3d25a13b2e234f5f7f7c13164d
- https://github.com/nats-io/nats-server/releases/tag/v2.11.16
- https://github.com/nats-io/nats-server/releases/tag/v2.12.7
- https://github.com/nats-io/nats-server/releases/tag/v2.14.0
- https://github.com/nats-io/nats-server/security/advisories/GHSA-jx8g-9g95-6322