RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Apr 2026Clear ×Project: NATSClear ×
NATSv2.14.0Networking & MessagingApr 30, 2026

A feature release adds JetStream, leafnode, configuration, and protocol capabilities alongside fixes. Operator attention is needed for the narrowed MQTT retained-message subject constraint and ACL updates when domain-aware acknowledgements and flow control are enabled; the Go toolchain version also changes.

Check if affected (1)

  • breakingThe retained-message subject constraint

    Applies if you use retained messages.

    Retained-message subjects can no longer contain the ASCII DEL character (0x7F). This constraint ships in v2.14.0.

Source
NATSv2.12.8Networking & MessagingApr 27, 2026

A maintenance release with a security fix, correctness fixes, a performance improvement, and dependency and toolchain manifest updates. Most changes take effect through the release itself without additional operator action.

Action needed (1)

  • securityBearer JWT disclosure fix in /connz

    The /connz monitoring endpoint no longer discloses bearer JWTs. The fix ships in the NATS monitoring endpoint.

Source
NATSv2.11.17Networking & MessagingApr 27, 2026

A maintenance release updates the Go toolchain and corrects NATS server defects. It includes fixes for bearer credential disclosure through monitoring and for redaction of route and cluster URL secrets.

Check if affected (2)

  • securityThe /connz endpoint no longer discloses bearer JWTs

    Applies if you use the /connz monitoring endpoint.

    The /connz monitoring endpoint no longer discloses bearer JWTs.

  • securityMonitoring redaction of route and cluster URL secrets

    Applies if you pass route and cluster URL secrets as command line arguments.

    Monitoring now redacts route and cluster URL secrets passed as command line arguments.

Source
NATSv2.12.7Networking & MessagingApr 14, 2026

A maintenance release with a dependency and toolchain update, configuration constraint changes, performance improvements, and correctness fixes. It also fixes an ACL permission bypass along with issues affecting leaf connections, streams, storage, and client authentication.

Check if affected (3)

  • securityQueue subscription enforcement of ACL deny patterns

    Applies if you use queue subscriptions and configure non-queue ACL deny patterns.

    Queue subscriptions can no longer incorrectly bypass non-queue ACL deny patterns.

  • breakingThe no_auth_user configuration field, restricted to client connections

    Applies if you configure no_auth_user.

    no_auth_user is now restricted to client connections only.

  • breakingDuplicate INFO permission updates for solicited leaf connections

    Applies if you use solicited leaf connections.

    Duplicate INFO permission updates are now accepted only for solicited leaf connections.

Source
NATSv2.11.16Networking & MessagingApr 14, 2026

This release updates the Go toolchain and corrects authorization, leafnode, and WebSocket behavior. Configuration rules for no_auth_user and duplicate leaf permission updates are narrower, so affected existing setups may require review.

Check if affected (2)

  • breakingThe no_auth_user connection scope restriction

    Applies if you configure no_auth_user.

    no_auth_user is restricted to client connections only.

  • breakingThe INFO permission update restriction

    Applies if you use solicited leaf connections.

    Duplicate INFO permission updates are accepted only for solicited leaf connections.

Source
Browse by month