A maintenance release with multiple disclosed security fixes, correctness fixes, stricter validation and permission constraints, and dependency and toolchain updates. It also includes fixes across MQTT, JetStream, leafnodes, WebSockets, monitoring, and clustering.
Action needed (1)
breakingThe
JWTsize limitJWTs now have a 1MB size limit.
Check if affected (11)
securityhighCVE-2026-33216, CVE-2026-33217, and CVE-2026-33215 fixes for MQTT systems
Applies if you use MQTT.
securityhighCVE-2026-33218 fix for leafnodes
Applies if you use leafnodes.
securityhighCVE-2026-33247 fix for command-line credentials
Applies if you configure credentials on the command line.
- + 8 more on the release page