GHSA-jxxm-27vp-c3m5

Suggest an improvement
Source
https://github.com/advisories/GHSA-jxxm-27vp-c3m5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jxxm-27vp-c3m5/GHSA-jxxm-27vp-c3m5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jxxm-27vp-c3m5
Aliases
Downstream
Related
Published
2026-03-24T21:44:17Z
Modified
2026-03-27T22:16:27.445993Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N CVSS Calculator
Summary
NATS allows MQTT clients to bypass ACL checks
Details

Background

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.

The nats-server provides an MQTT client interface.

Problem Description

When using ACLs on message subjects, these ACLs were not applied in the $MQTT.> namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects.

Affected Versions

Any version before v2.12.6 or v2.11.15

Workarounds

None.

Database specific
{
    "nvd_published_at": "2026-03-25T20:16:32Z",
    "github_reviewed_at": "2026-03-24T21:44:17Z",
    "cwe_ids": [
        "CWE-863"
    ],
    "severity": "HIGH",
    "github_reviewed": true
}
References

Affected packages

Go / github.com/nats-io/nats-server/v2

Package

Name
github.com/nats-io/nats-server/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/nats-io/nats-server/v2

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.11.15

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jxxm-27vp-c3m5/GHSA-jxxm-27vp-c3m5.json"

Go / github.com/nats-io/nats-server/v2

Package

Name
github.com/nats-io/nats-server/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/nats-io/nats-server/v2

Affected ranges

Type
SEMVER
Events
Introduced
2.12.0-RC.1
Fixed
2.12.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jxxm-27vp-c3m5/GHSA-jxxm-27vp-c3m5.json"

Go / github.com/nats-io/nats-server

Package

Name
github.com/nats-io/nats-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/nats-io/nats-server

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jxxm-27vp-c3m5/GHSA-jxxm-27vp-c3m5.json"