Skip to content

Incomplete fix for CVE-2026-33249: Leaf node connections bypass Nats-Trace-Dest permission check

Moderate
neilalexander published GHSA-p3j5-5hrq-p75h Jun 29, 2026

Package

gomod github.com/nats-io/nats-server/v2 (Go)

Affected versions

<= 2.14.2, <= 2.12.7

Patched versions

2.14.3, 2.12.8

Description

Background

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT and edge computing.

The NATS Server supports leafnode connections between servers and message tracing through NATS headers.

Problem Description

Message trace destination checks were applied to ordinary client connections but not consistently to messages arriving through leafnode connections.

A leafnode operator could cause trace events to be sent to subjects that would not otherwise be permitted and could use trace-only behavior to prevent normal delivery or storage of affected messages.

Trace events can include routing, subscription, account, service import and JetStream metadata. The payload of the original application message is not chosen through the trace event itself.

Affected Versions

Versions v2.14.2, v2.12.7 and below are vulnerable. The issue is fixed in v2.14.3 and v2.12.8.

Workarounds

Where possible, avoid granting publish paths from less-trusted leaf nodes into subjects for which trace-only behavior would affect delivery guarantees. No other known workarounds are available aside from upgrading to a fixed release.

References

Severity

Moderate

CVE ID

CVE-2026-58254

Weaknesses

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. Learn more on MITRE.

Credits