RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Mar 2026Clear ×Project: NATSClear ×
NATSv2.12.6Networking & MessagingMar 24, 2026

A maintenance release with multiple security fixes, tighter JWT and MQTT-related enforcement, and dependency manifest updates. It also includes correctness fixes and improvements across networking, monitoring, clustering, and JetStream.

Action needed (1)

  • breakingJWT size limit

    JWTs now have a 1MB size limit.

Check if affected (13)

Source
NATSv2.11.15Networking & MessagingMar 24, 2026

A maintenance release with multiple disclosed security fixes, correctness fixes, stricter validation and permission constraints, and dependency and toolchain updates. It also includes fixes across MQTT, JetStream, leafnodes, WebSockets, monitoring, and clustering.

Action needed (1)

  • breakingThe JWT size limit

    JWTs now have a 1MB size limit.

Check if affected (11)

  • securityhighCVE-2026-33216, CVE-2026-33217, and CVE-2026-33215 fixes for MQTT systems

    Applies if you use MQTT.

    This release fixes CVE-2026-33216, CVE-2026-33217, and CVE-2026-33215 in systems using MQTT.

  • securityhighCVE-2026-33218 fix for leafnodes

    Applies if you use leafnodes.

    This release fixes CVE-2026-33218 in systems using leafnodes.

  • securityhighCVE-2026-33247 fix for command-line credentials

    Applies if you configure credentials on the command line.

    This release fixes CVE-2026-33247 in systems providing credentials on the command line.

  • + 8 more on the release page
Source
NATSv2.12.5Networking & MessagingMar 9, 2026

A maintenance release with fixes for two CVEs, many correctness issues, expanded JetStream configuration capabilities, and dependency updates. Operators of clustered deployments should review the documented regression affecting stream updates and the changed max_conns behavior.

Check if affected (3)

  • securityCVE-2026-29785 fix for leafnode compression

    Applies if leafnode compression is enabled.

    Fixes CVE-2026-29785 in systems with leafnode compression enabled.

  • securityCVE-2026-27889 fix for WebSockets

    Applies if WebSockets are enabled.

    Fixes CVE-2026-27889 in systems with WebSockets enabled.

  • breakingThe max_conns server configuration value

    Applies if you configure max_conns in the server configuration.

    The server configuration now accepts 0 for max_conns, which rejects all incoming client connections.

Source
NATSv2.11.14Networking & MessagingMar 9, 2026

A maintenance release with two security fixes, a Go toolchain version change, and several WebSockets correctness fixes. The WebSockets changes cover compressed frame negotiation, protocol validation, connection upgrades, frame validation, compressor state, and empty compressed buffers.

Check if affected (2)

  • securityhighCVE-2026-29785 fix for leafnode compression

    Applies if CVE-2026-29785 is present and leafnode compression is enabled.

    The release fixes CVE-2026-29785 in systems with leafnode compression enabled.

  • securityhighCVE-2026-27889 fix for WebSockets

    Applies if CVE-2026-27889 is present and WebSockets is enabled.

    The release fixes CVE-2026-27889 in systems with WebSockets enabled.

Source
Browse by month