A high-severity flaw in NATS Server tracked as CVE-2026-58253 allows unauthenticated peers to bypass authentication on inter-server route and leafnode listeners when the no_auth_user option is enabled. The bug stems from a parser fast path that was meant for ordinary client connections but was incorrectly applied to non-client connection types, allowing an attacker to skip the required CONNECT authentication step and inherit the privileges of that server-to-server connection. The issue is rated CVSS 8.8 and mapped to CWE-287 Improper Authentication.
Maintainers fixed the problem by restricting no_auth_user behavior to client connections only and enforcing that route, leafnode, and some gateway connections must begin with CONNECT before other protocol messages are accepted. Associated tests show that non-client peers sending PING first are now rejected, direct route-protocol message injection such as RMSG without CONNECT is blocked, and normal client behavior remains unchanged when no_auth_user is configured. The vulnerability affects releases before 2.14.0, 2.12.7, and 2.11.16, which contain the fix.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-58253 was disclosed as a high-severity improper authentication flaw in NATS Server affecting inter-server route and leafnode listeners when no_auth_user is configured. The advisory said versions prior to 2.14.0, 2.12.7, and 2.11.16 are affected and that the issue is fixed in those releases, with a CVSS 8.8 score.
Further NATS Server commits applied the same authentication/parsing fix, again limiting NoAuthUser behavior to client connections and preventing non-client protocol handling before CONNECT. The changes preserved normal client behavior while blocking abuse on route and leafnode listeners.
A NATS Server code change restricted the NoAuthUser fast-path to CLIENT connections only, requiring ROUTER, LEAF, and certain GATEWAY connections to begin with CONNECT. Associated tests verified that route and leaf connections sending PING first or injecting route messages without CONNECT are rejected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.