Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-58209

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not consistently recheck the concrete original topic before sending the MQTT PUBLISH to the subscriber. This issue is fixed in versions 2.14.3 and 2.12.12.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
Версия до 2.12.12 (исключая)
cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:*
Версия от 2.14.0 (включая) до 2.14.3 (исключая)

EPSS

Процентиль: 17%
0.00251
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
ubuntu
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not consistently recheck the concrete original topic before sending the MQTT PUBLISH to the subscriber. This issue is fixed in versions 2.14.3 and 2.12.12.

CVSS3: 4.3
msrc
23 дня назад

NATS Server: MQTT retained and QoS replay bypass subscribe deny filters

CVSS3: 4.3
debian
25 дней назад

NATS Server is a high-performance server for NATS.io, the cloud and ed ...

EPSS

Процентиль: 17%
0.00251
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863