CVE detail
CVE-2026-58253
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could also apply to route or leafnode listeners, allowing an unauthenticated peer to bypass inter-server CONNECT authentication and operate with the privileges associated with that connection type. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- CVE-2026-58253 NATS Server: Route API Auth BypassMicrosoft MSRC
Information published.
vendormsrc.microsoft.comJul 11, 2026, 8:08 AM No excerpt available.
Exploitgithub.comJul 8, 2026, 8:16 PMNo excerpt available.
Exploitgithub.comJul 8, 2026, 8:16 PMNo excerpt available.
Exploitgithub.comJul 8, 2026, 8:16 PMNo excerpt available.
Exploitgithub.comJul 8, 2026, 8:16 PMNo excerpt available.
Exploitgithub.comJul 8, 2026, 8:16 PMNo excerpt available.
Exploitgithub.comJul 8, 2026, 8:16 PMNo excerpt available.
Exploitgithub.comJul 8, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-33248CVSS 4.2 · Medium
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `ve…
- CVE-2026-33246CVSS 6.4 · Medium
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message header, providing information…
- CVE-2026-33215CVSS 6.5 · Medium
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.…
- CVE-2026-40920CVSS N/A · Unrated
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
- CVE-2026-19342CVSS 5.5 · Medium
A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation…
- CVE-2026-15038CVSS 9.8 · Critical
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordP…