RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: NATSClear ×
NATSv2.12.14Networking & MessagingJul 30, 2026

A maintenance release with a Go toolchain update, dependency manifest updates, JetStream performance and configuration changes, and numerous correctness fixes. Authentication fixes address security flaws and require upgrading.

Action needed (1)

  • breakingThe disk concurrency semaphore, increased to 4096 slots

    The disk concurrency semaphore is now set to 4096 slots, up from the previous CPU-scaled count. This performance change ships in v2.12.14.

Check if affected (2)

  • securityAuthentication checks with no_auth_user and auth callouts

    Applies if you configure no_auth_user and use auth callouts.

    Authentication checks are no longer skipped when no_auth_user is combined with auth callouts and no CONNECT message is sent. This security fix ships in v2.12.14.

  • securityTLS verify_and_map authentication with blank passwords

    Applies if you use TLS and configure verify_and_map.

    An authentication bypass involving TLS verify_and_map and users with blank passwords is fixed. This security fix ships in v2.12.14.

Source
NATSv2.12.6Networking & MessagingMar 24, 2026

A maintenance release with multiple security fixes, tighter JWT and MQTT-related enforcement, and dependency manifest updates. It also includes correctness fixes and improvements across networking, monitoring, clustering, and JetStream.

Action needed (1)

  • breakingJWT size limit

    JWTs now have a 1MB size limit.

Check if affected (13)

Source
NATSv2.11.15Networking & MessagingMar 24, 2026

A maintenance release with multiple disclosed security fixes, correctness fixes, stricter validation and permission constraints, and dependency and toolchain updates. It also includes fixes across MQTT, JetStream, leafnodes, WebSockets, monitoring, and clustering.

Action needed (1)

  • breakingThe JWT size limit

    JWTs now have a 1MB size limit.

Check if affected (11)

  • securityhighCVE-2026-33216, CVE-2026-33217, and CVE-2026-33215 fixes for MQTT systems

    Applies if you use MQTT.

    This release fixes CVE-2026-33216, CVE-2026-33217, and CVE-2026-33215 in systems using MQTT.

  • securityhighCVE-2026-33218 fix for leafnodes

    Applies if you use leafnodes.

    This release fixes CVE-2026-33218 in systems using leafnodes.

  • securityhighCVE-2026-33247 fix for command-line credentials

    Applies if you configure credentials on the command line.

    This release fixes CVE-2026-33247 in systems providing credentials on the command line.

  • + 8 more on the release page
Source
Browse by month