Debian Package Tracker
Register | Log in
Subscribe

nats-server

High-Performance server for NATS.io (program)

Choose email to subscribe with

general
  • source: nats-server (main)
  • version: 2.10.27-1
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Dominik George [DMD]
  • arch: all any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 2.9.10-1
  • testing: 2.10.27-1
  • unstable: 2.10.27-1
versioned links
  • 2.9.10-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.10.27-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-nats-io-nats-server-dev
  • nats-server
action needed
A new upstream version is available: 2.11.4 high
A new upstream version 2.11.4 is available, you should consider packaging it.
Created: 2025-01-11 Last update: 2025-05-31 22:56
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2025-30215: NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.27 and 2.11.1, the management of JetStream assets happens with messages in the $JS. subject namespace in the system account; this is partially exposed into regular accounts to allow account holders to manage their assets. Some of the JS API requests were missing access controls, allowing any user with JS management permissions in any account to perform certain administrative actions on any JS asset in any other account. At least one of the unprotected APIs allows for data destruction. None of the affected APIs allow disclosing stream contents. This vulnerability is fixed in v2.11.1 or v2.10.27.
1 issue left for the package maintainer to handle:
  • CVE-2023-47090: (needs triaging) NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-10-28 Last update: 2025-04-16 03:31
Depends on packages which need a new maintainer normal
The packages that nats-server depends on which need a new maintainer are:
  • golang-github-nats-io-nuid (#940402)
    • Depends: golang-github-nats-io-nuid-dev
    • Build-Depends: golang-github-nats-io-nuid-dev
Created: 2022-06-04 Last update: 2025-05-31 22:01
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2025-04-10 Last update: 2025-04-10 09:31
news
[rss feed]
  • [2025-04-12] nats-server 2.10.27-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-09] Accepted nats-server 2.10.27-1 (source) into unstable (Mathias Gibbens)
  • [2024-12-28] nats-server 2.10.24-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-26] Accepted nats-server 2.10.24-1 (source) into unstable (Mathias Gibbens)
  • [2024-07-25] nats-server 2.10.18-1 MIGRATED to testing (Debian testing watch)
  • [2024-07-22] Accepted nats-server 2.10.18-1 (source) into unstable (Mathias Gibbens)
  • [2024-06-24] nats-server 2.10.16-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-21] Accepted nats-server 2.10.16-1 (source) into unstable (Mathias Gibbens)
  • [2023-12-24] nats-server 2.10.7-1 MIGRATED to testing (Debian testing watch)
  • [2023-12-22] Accepted nats-server 2.10.7-1 (source) into unstable (Mathias Gibbens)
  • [2023-11-05] nats-server 2.10.4-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-05] nats-server 2.10.4-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-02] Accepted nats-server 2.10.4-1 (source) into unstable (Mathias Gibbens)
  • [2023-10-22] nats-server 2.10.3-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-15] Accepted nats-server 2.10.3-1 (source) into unstable (Mathias Gibbens)
  • [2023-09-26] nats-server 2.10.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-24] Accepted nats-server 2.10.1-1 (source) into unstable (Mathias Gibbens)
  • [2023-07-10] nats-server 2.9.19-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-08] Accepted nats-server 2.9.19-1 (source) into unstable (Mathias Gibbens)
  • [2022-12-26] nats-server 2.9.10-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-24] Accepted nats-server 2.9.10-1 (source) into unstable (Mathias Gibbens)
  • [2022-11-29] nats-server 2.9.8-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-26] Accepted nats-server 2.9.8-1 (source) into unstable (Mathias Gibbens)
  • [2022-06-07] Accepted nats-server 2.8.0-2 (source) into unstable (Mike Gabriel)
  • [2022-06-04] Accepted nats-server 2.8.0-1 (source all amd64) into unstable, unstable (Debian FTP Masters) (signed by: Dominik George)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.10.27-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing