A maintenance release with fixes for two CVEs, many correctness issues, expanded JetStream configuration capabilities, and dependency updates. Operators of clustered deployments should review the documented regression affecting stream updates and the changed max_conns behavior.
Check if affected (3)
securityCVE-2026-29785 fix for leafnode compression
Applies if leafnode compression is enabled.
securityCVE-2026-27889 fix for
WebSocketsApplies if
WebSocketsare enabled.breakingThe
max_connsserver configuration valueApplies if you configure
max_connsin the server configuration.