A maintenance release with multiple security fixes, tighter JWT and MQTT-related enforcement, and dependency manifest updates. It also includes correctness fixes and improvements across networking, monitoring, clustering, and JetStream.
Action needed (1)
breakingJWT size limit
JWTs now have a
1MBsize limit.
Check if affected (13)
securityhighMQTT security fixes
Applies if you use
MQTT.Fixes CVE-2026-33216, CVE-2026-33217, and CVE-2026-33215 in systems using
MQTT.securityhighLeafnode security fix
Applies if you use
leafnodes.Fixes CVE-2026-33218 in systems using
leafnodes.securityhighCommand-line credential security fix
Applies if you provide credentials on the command line.
Fixes CVE-2026-33247 in systems providing credentials on the command line.
- + 10 more on the release page