Data

NATS: what changed

In the last 90 days, 10 summarized changes: 5 releases, 5 fixes. Stackdiff reads NATS's own feeds (github.com) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

2.14.7-RC.1Release
Release v2.14.7-RC.1
2.15.0-RC.1Release
Release v2.15.0-RC.1
2.14.6Fix
Release v2.14.6
2.14.6-RC.2Fix
Release v2.14.6-RC.2
2.14.6-RC.1Fix
Release v2.14.6-RC.1
2.15.0-preview.1Release
Release v2.15.0-preview.1
2.14.5Fix
Release v2.14.5
2.12.15Fix
Release v2.12.15
2.14.4Release
Release v2.14.4
2.12.14Release
Release v2.12.14
2.11.14Securityhigh
GHSA-pq2q-rcw4-3hr6: NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
2.11.15Securityhigh
GHSA-3f24-pcvm-5jqc: NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
2.11.15Securityhigh
GHSA-55h8-8g96-x4hj: NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
2.11.15Securityhigh
GHSA-pwx7-fx9r-hr4h: NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
2.11.15Securityhigh
GHSA-9983-vrx2-fg9c: NATS JetStream has an authorization bypass through its Management API
2.11.15Securityhigh
GHSA-8r68-gvr4-jh7j: NATS is vulnerable to pre-auth DoS through WebSockets client service
2.11.15Securityhigh
GHSA-vprv-35vv-q339: NATS has pre-auth server panic via leafnode handling
2.11.15Securityhigh
GHSA-jxxm-27vp-c3m5: NATS allows MQTT clients to bypass ACL checks
2.11.15Securityhigh
GHSA-v722-jcv5-w7mc: NATS has MQTT plaintext password disclosure
2.11.15Securityhigh
GHSA-fcjp-h8cc-6879: NATS is vulnerable to MQTT hijacking via Client ID
2.11.14Securityhigh
GHSA-52jh-2xxh-pwh6: NATS Server panic via malicious compression on leafnode port
2.11.15Securityhigh
GHSA-x6g4-f6q3-fqvv: NATS credentials are exposed in monitoring port via command-line argv
2.11.15Securityhigh
GHSA-8m2x-3m6q-6w8j: NATS: Message tracing can be redirected to arbitrary subject
2.11.12Securitymedium
GHSA-qrvq-68c2-7grw: nats-server websockets are vulnerable to pre-auth memory DoS
2.10.27Securitymedium
GHSA-fhg8-qxh5-7q3w: NATS Server may fail to authorize certain Jetstream admin APIs
2.2.3Securitymedium
GHSA-jj54-5q2m-q7pj: NATS server TLS missing ciphersuite settings when CLI flags used
0.4.6Securityhigh
GHSA-mr45-rx8q-wcm9: xkeys seal encryption used fixed key for all encryption
2.10.2Securityhigh
GHSA-fr2g-9hjm-wr23: NATS.io: Adding accounts for just the system account adds auth bypass
2.2.0Securityhigh
GHSA-m4jx-6526-vvhm: Denial of service in github.com/nats-io/nats-server/server
2.2.0Securitymedium
GHSA-j756-f273-xhp4: github.com/nats-io/nats-server Import token permissions checking not enforced

Where Stackdiff reads NATS

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get NATS changes in your Monday brief

Add NATS and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief

Other data tools