Executive brief
NATS Server is a high-performance messaging system used for cloud and edge computing to route data between different applications. A security flaw in how the server handles access control rules allowed authenticated users to bypass restrictions and receive messages they were supposed to be blocked from seeing. This could lead to the unauthorized exposure of sensitive data transmitted across the messaging network.
Technical details
An authorization bypass vulnerability exists in NATS Server's ACL enforcement mechanism. The root cause is the use of `subjectIsSubsetMatch` in the `client.canSubscribe` method, which failed to account for overlapping wildcard patterns that were not strict subsets (e.g., a subscription to 'foo.*' could receive messages from a denied subject like '*.secret'). An authenticated attacker can exploit this by crafting specific wildcard subscriptions to intercept messages on subjects they are explicitly denied access to. Additionally, queue subscriptions could interfere with delivery to legitimate consumers. The fix replaces the vulnerable logic with `SubjectsCollide` to properly detect intersections between wildcard subjects. Patches are available in versions 2.11.16, 2.12.7, and 2.14.0.
Affected products
- nats-io nats-server < 2.11.16, >= 2.12.0-preview.1 < 2.12.7, < 2.14.0
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
- 2026-04-14: patched: Initial patches for 2.11 and 2.12 branches released
References
- https://github.com/nats-io/nats-server/commit/8ced85a11497f86704a95d960281480ce037386b
- https://github.com/nats-io/nats-server/commit/a42a6d1e258eb5c3a2190384d31965a4b715e854
- https://github.com/nats-io/nats-server/commit/e611ca9604697b02d8f22beb76037400a9cf72e6
- https://github.com/nats-io/nats-server/releases/tag/v2.11.16
- https://github.com/nats-io/nats-server/releases/tag/v2.12.7
- https://github.com/nats-io/nats-server/releases/tag/v2.14.0
- https://github.com/nats-io/nats-server/security/advisories/GHSA-wh7g-5m82-pmhr