CVE-2026-58213
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode connections, corrupting the forwarded protocol stream and allowing injection of unintended NATS protocol operations. This issue is fixed in versions 2.14.1 and 2.12.9.
취약점 유형
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode connections, corrupting the forwarded protocol stream and allowing injection of unintended NATS protocol operations. This issue is fixed in versions 2.14.1 and 2.12.9.
영향받는 제품
- linuxfoundation nats-server
참고 자료
- https://github.com/nats-io/nats-server/commit/366837cfc65ab9ccb4f98193c65e8daf238582d8
- https://github.com/nats-io/nats-server/commit/64ebae40051ee497c481e10f316238faf0de1736
- https://github.com/nats-io/nats-server/commit/f14856b9e57a36818f43851cb69b6e33670885c9
- https://github.com/nats-io/nats-server/pull/8163
- https://github.com/nats-io/nats-server/pull/8164
- https://github.com/nats-io/nats-server/releases/tag/v2.12.9
공격자보다 먼저 취약점을 찾으세요.
GitHub로 로그인하고 1분 안에 첫 감사를 실행하세요. 무료 플랜은 신용카드가 필요 없습니다.