The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
{ "binaries": [ { "binary_version": "0.0~git20181120.285cf2c-4", "binary_name": "golang-github-nats-io-jwt-dev" } ] }
{ "binaries": [ { "binary_version": "0.0~git20181120.285cf2c-4.1", "binary_name": "golang-github-nats-io-jwt-dev" } ] }