Skip to content
VulniPulse
High8.8Red Hat Linux

High [CVE-2026-58253] Authentication bypass and privilege escalation via parser fast path

This high-severity Red Hat Linux advisory covers CVE-2026-58253.

CVE-2026-58253 Published Jul 8, 2026Updated by vendor Jul 8, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system.

Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, a parser fast path intended for ordinary client connections could also apply to route or leafnode listeners, allowing an unauthenticated peer to bypass inter-server CONNECT authentication and operate with the privileges associated with that connection type.

This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16. A flaw was found in NATS Server.

This allows an unauthenticated attacker on an adjacent network to bypass inter-server authentication. Consequently, the attacker can operate with the privileges of a trusted connection, leading to a high impact on data integrity.

Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L). Weakness: CWE-551.

Red Hat lists Red Hat Hardened Images as not affected.

Affected versions
  • < 2.14.0
  • < 2.12.7
  • < 2.11.16

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Fixed versions
  • 2.14.0
  • 2.12.7
  • 2.11.16

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, avoid enabling the `no_auth_user` configuration in NATS Server. If `no_auth_user` is required, restrict network access to NATS route and leafnode listeners using firewall rules to only trusted hosts and networks. This limits the attack surface by preventing unauthenticated access from adjacent networks. A restart of the NATS server may be required for configuration changes to take effect.

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.