# NATS changelog > A connective technology for cloud, edge and IoT messaging. - Vendor: Synadia - Category: Developer Tools - Official site: https://nats.io - Tracked by: What's New (https://whatsnew.fyi/product/nats) - Harvested from: GitHub (nats-io/nats-server) - Entries below: 10 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. ## Releases ### v2.14.4 — Release v2.14.4 - Date: 2026-07-30 - Version: v2.14.4 - Original notes: https://github.com/nats-io/nats-server/releases/tag/v2.14.4 - Permalink: https://whatsnew.fyi/product/nats/releases/v2.14.4 - **changed** — Go version updated to 1.26.5 - **changed** — github.com/klauspost/compress updated to v1.19.0 - **changed** — golang.org/x/crypto updated to v0.54.0 - **changed** — golang.org/x/sys updated to v0.47.0 - **changed** — github.com/antithesishq/antithesis-sdk-go updated to v0.7.2-default-no-op - **changed** — Raft transport layer has been decoupled to improve testing - **changed** — Disk concurrency semaphore increased to 4096 slots from the previous CPU-scaled count - **added** — Disk concurrency semaphore can now be configured with the max_concurrent_io option in the jetstream config block - **changed** — Filestore underlying block cache buffers are now recycled to the pool when the weak reference is collected by the GC - **changed** — Calculating and looking up sequences in delete maps for file-backed streams with large numbers of interior deletes is now faster and holds locks for less time - **changed** — Inserts, iterations and deletes in AVL sequence sets are now faster in many cases - **changed** — Stream snapshots now attempt to determine the correct encode buffer size up front - **changed** — Reduced memory usage of the structure used to track subjects within a stream - **fixed** — allow_non_tls will no longer log an incorrect message at startup claiming that TLS is required - **fixed** — Combining no_auth_user with auth callouts will no longer skip authentication checks when no CONNECT message is sent - **fixed** — JWT validation no longer crashes the server with whitespace-only permissions - **fixed** — Several paths that enforce the permissions of queue subscriptions no longer treat the whole permission as a subject literal - **fixed** — Several JetStream and MQTT endpoints now correctly guard against null values in JSON - **security** — Fixed an authentication bypass with TLS verify_and_map authenticating users with blank passwords - **fixed** — The healthz endpoint will now skip and no longer report on expired JWT accounts ##### Changelog Refer to the [2.14 Upgrade Guide](https://docs.nats.io/release-notes/whats_new/whats_new_214) for backwards compatibility notes with 2.12.x. Please note that the 2.13.x version was skipped. ###### Go Version - 1.26.5 (#8435) ###### Dependencies - github.com/klauspost/compress v1.19.0 (#8385) - golang.org/x/crypto v0.54.0 (#8385) - golang.org/x/sys v0.47.0 (#8385) - github.com/antithesishq/antithesis-sdk-go v0.7.2-default-no-op (#8385) ###### Improved JetStream - The Raft transport layer has been decoupled, improves testing but does not change server behaviour (#8181) - The disk concurrency semaphore has been increased to 4096 slots, up from the previous CPU-scaled count (#8336) - The disk concurrency semaphore can now be configured with the `max_concurrent_io` option in the `jetstream` config block (#8336) - Filestore underlying block cache buffers are now recycled to the pool when the weak reference is collected by the GC, which should smooth out memory usage with some usage patterns (#8395) - Calculating and looking up sequences in delete maps for file-backed streams with large numbers of interior deletes is now faster and holds locks for less time (#8403) - Inserts, iterations and deletes in AVL sequence sets are now faster in many cases, which speeds up the tracking of interior deletes (#8406) - Stream snapshots now attempt to determine the correct encode buffer size up front, avoiding many unnecessary allocations on streams with large numbers of interior deletes (#8405) - Reduced memory usage of the structure that is used to track subjects within a stream (#8412) ###### Fixed General - `allow_non_tls` will no longer log an incorrect message at startup claiming that TLS is required (#8420) - Combining `no_auth_user` with auth callouts will no longer skip authentication checks when no `CONNECT` message is sent - JWT validation no longer crashes the server with whitespace-only permissions - Several paths that enforce the permissions of queue subscriptions no longer treat the whole permission as a subject literal - Several JetStream and MQTT endpoints now correctly guard against null values in JSON - Fixed an authentication bypass with TLS `verify_and_map` authenticating users with blank passwords Monitoring - The `healthz` endpoint will now skip and no longer report on expired JWT accounts (#8379, thanks to @ByapakSigdel) - The `varz` endpoint will now correctly report JetStream limits after they were changed via a config reload (#8394) JetStream - Malformed cluster replicated acks or delivered updates are now correctly rejected by the decoder (#8284, thanks to @uwezkhan) - Malformed cluster replicated skip or reset updates are now correctly rejected by the decoder (#8345, thanks to @uwezkhan) - Empty cluster replicated entries are now correctly ignored (#8347, thanks to @uwezkhan) - Decoded AVL sequence set node counts are now validated correctly on 32-bit systems (#8355, thanks to @uwezkhan) - Stale error responses on source or mirror creation are now dropped by recreating the subscription (#8356) - Oversized cluster replicated messages are now validated correctly on 32-bit systems (#8357, thanks to @uwezkhan) - Raft elections now correctly ignore votes from removed peers (#8353) - Filestore blocks with unsynced or truncated key files are now removed and counted as lost data instead of failing to recover altogether (#8365) - Filestore encryption key files are now synced to disk more aggressively (#8366) - Raft now handles the append entry iterator returning no more entries correctly (#8372) - Fixed string ownership when handling the expected last sequence per subject in a batch (#8377) - Fixed a race condition between concurrent message removals via limits that could unexpectedly disable writes into a filestore (#8378) - Fixed a bug in the filestore which could prevent some filestore block cache references from being weakened correctly _[Truncated at 4000 characters — full notes: https://github.com/nats-io/nats-server/releases/tag/v2.14.4]_ ### v2.12.14 — Release v2.12.14 - Date: 2026-07-30 - Version: v2.12.14 - Original notes: https://github.com/nats-io/nats-server/releases/tag/v2.12.14 - Permalink: https://whatsnew.fyi/product/nats/releases/v2.12.14 - **changed** — Increase disk concurrency semaphore to 4096 slots, up from the previous CPU-scaled count - **added** — Add max_concurrent_io option in the jetstream config block to configure disk concurrency semaphore - **changed** — Recycle filestore underlying block cache buffers to the pool when the weak reference is collected by the GC - **changed** — Improve performance of inserts, iterations and deletes in AVL sequence sets - **changed** — Stream snapshots now determine the correct encode buffer size up front to avoid unnecessary allocations - **changed** — Reduce memory usage of the structure that tracks subjects within a stream - **fixed** — allow_non_tls will no longer log an incorrect message at startup claiming that TLS is required - **fixed** — Combining no_auth_user with auth callouts will no longer skip authentication checks when no CONNECT message is sent - **fixed** — JWT validation no longer crashes the server with whitespace-only permissions - **security** — Fix authentication bypass with TLS verify_and_map authenticating users with blank passwords - **fixed** — The healthz endpoint will now skip and no longer report on expired JWT accounts - **fixed** — The varz endpoint will now correctly report JetStream limits after they were changed via a config reload - **fixed** — Malformed cluster replicated acks or delivered updates are now correctly rejected by the decoder - **fixed** — Malformed cluster replicated skip or reset updates are now correctly rejected by the decoder - **fixed** — Raft elections now correctly ignore votes from removed peers - **fixed** — Filestore encryption key files are now synced to disk more aggressively - **fixed** — Attempting to update the consumer storage type now correctly returns an error - **fixed** — Stream publish checks will now correctly reject messages that exceed the maximum store size before proposal - **fixed** — Creating a clustered consumer immediately after creating a clustered stream should no longer respond with a stream not found error - **fixed** — MQTT packet identifiers for QoS1 and QoS2 are now issued by a monotonic counter, avoiding accidental ID reuse ##### Changelog ###### Go Version - 1.25.12 (#8435) ###### Dependencies - github.com/klauspost/compress v1.19.0 (#8385) - golang.org/x/crypto v0.54.0 (#8385) - golang.org/x/sys v0.47.0 (#8385) - github.com/antithesishq/antithesis-sdk-go v0.7.2-default-no-op (#8385) ###### Improved JetStream - The Raft transport layer has been decoupled, improves testing but does not change server behaviour (#8181) - The disk concurrency semaphore has been increased to 4096 slots, up from the previous CPU-scaled count (#8336) - The disk concurrency semaphore can now be configured with the `max_concurrent_io` option in the `jetstream` config block (#8336) - Filestore underlying block cache buffers are now recycled to the pool when the weak reference is collected by the GC, which should smooth out memory usage with some usage patterns (#8395) - Inserts, iterations and deletes in AVL sequence sets are now faster in many cases, which speeds up the tracking of interior deletes (#8406) - Stream snapshots now attempt to determine the correct encode buffer size up front, avoiding many unnecessary allocations on streams with large numbers of interior deletes (#8405) - Reduced memory usage of the structure that is used to track subjects within a stream (#8412) ###### Fixed General - `allow_non_tls` will no longer log an incorrect message at startup claiming that TLS is required (#8420) - Combining `no_auth_user` with auth callouts will no longer skip authentication checks when no `CONNECT` message is sent - JWT validation no longer crashes the server with whitespace-only permissions - Several paths that enforce the permissions of queue subscriptions no longer treat the whole permission as a subject literal - Several JetStream and MQTT endpoints now correctly guard against null values in JSON - Fixed an authentication bypass with TLS `verify_and_map` authenticating users with blank passwords Monitoring - The `healthz` endpoint will now skip and no longer report on expired JWT accounts (#8379, thanks to @ByapakSigdel) - The `varz` endpoint will now correctly report JetStream limits after they were changed via a config reload (#8394) JetStream - Malformed cluster replicated acks or delivered updates are now correctly rejected by the decoder (#8284, thanks to @uwezkhan) - Malformed cluster replicated skip or reset updates are now correctly rejected by the decoder (#8345, thanks to @uwezkhan) - Empty cluster replicated entries are now correctly ignored (#8347, thanks to @uwezkhan) - Decoded AVL sequence set node counts are now validated correctly on 32-bit systems (#8355, thanks to @uwezkhan) - Oversized cluster replicated messages are now validated correctly on 32-bit systems (#8357, thanks to @uwezkhan) - Raft elections now correctly ignore votes from removed peers (#8353) - Filestore encryption key files are now synced to disk more aggressively (#8366) - Raft now handles the append entry iterator returning no more entries correctly (#8372) - Fixed a bug in the filestore which could prevent some filestore block cache references from being weakened correctly, which could result in unexpected memory usage and GC pressure (#8380) - Attempting to update the consumer storage type now correctly returns an error (#8382) - Stream publish checks will now correctly reject messages that exceed the maximum store size before proposal (#8389) - Creating a clustered consumer immediately after creating a clustered stream should no longer respond with a `stream not found` error (#8410) - Replicated streams that were recreated while a node was down are no longer treated as an update by a returning node processing a snapshot, avoiding stale Raft groups from continuing to run and unexpected behaviour with consumers (#8413) - Stream snapshot endpoints now more strictly check the reply subject for validity MQTT - Packet identifiers for QoS1 and QoS2 are now issued by a monotonic counter, avoiding acciden _[Truncated at 4000 characters — full notes: https://github.com/nats-io/nats-server/releases/tag/v2.12.14]_ ### v2.14.3 — Release v2.14.3 - Date: 2026-06-29 - Version: v2.14.3 - Original notes: https://github.com/nats-io/nats-server/releases/tag/v2.14.3 - Permalink: https://whatsnew.fyi/product/nats/releases/v2.14.3 - **changed** — Per-connection log lines have been demoted to debug level - **changed** — Writer options are now applied consistently when using the s2_fast compression mode - **changed** — Stream and consumer assignment handling has been refactored for more consistent migration and info behavior - **changed** — Meta, stream and consumer write errors are now registered more consistently for health and recovery handling - **removed** — JSONP callback support has been removed from monitoring endpoints - **fixed** — Long-running reconnect and OCSP loops no longer retain unused timers, reducing memory pressure over time - **fixed** — Inherited JWT default permissions are now refreshed when account claims are updated - **fixed** — External auth configuration is now cleared correctly when account claims are updated - **fixed** — PROXY protocol detection, TLS sniffing with allow_non_tls and PROXY v1 address-family parsing have been fixed - **fixed** — A race in gateway CONNECT handling has been fixed - **fixed** — Trusted proxy tracking no longer leaks closed clients during concurrent updates - **fixed** — Service import replies can now be delivered across cluster routes - **fixed** — Message tracing now works correctly with service imports and exports - **fixed** — NoAuthUser now checks connection restrictions - **fixed** — Leaf connections no longer bypass Nats-Trace-Dest publish permission checks - **fixed** — CONNZ and SUBSZ pagination now guard against Offset and Limit integer overflow panics - **fixed** — Fixed a nil pointer panic when starting up when the resolver parent directory is missing - **fixed** — Partial CONNECT packets can no longer exhaust pre-authentication memory - **fixed** — PUBLISH remaining-length underflow no longer causes a server panic ##### Changelog Refer to the [2.14 Upgrade Guide](https://docs.nats.io/release-notes/whats_new/whats_new_214) for backwards compatibility notes with 2.12.x. Please note that the 2.13.x version was skipped. ###### Go Version - 1.26.4 (#8281) ###### Dependencies - golang.org/x/crypto v0.53.0 (#8297) - golang.org/x/sys v0.46.0 (#8297) - github.com/nats-io/jwt/v2 v2.8.2 - github.com/nats-io/nkeys v0.4.16 ###### Improved General - Per-connection log lines that could be noisy in normal operation have been demoted to debug level (#8289) - Writer options are now applied consistently when using the `s2_fast` compression mode (#8047) JetStream - Stream and consumer assignment handling has been refactored for more consistent migration and info behavior (#8262) - Meta, stream and consumer write errors are now registered more consistently for health and recovery handling (#8293) ###### Removed Monitoring - JSONP callback support has been removed from monitoring endpoints ###### Fixed General - Long-running reconnect and OCSP loops no longer retain unused timers, reducing memory pressure over time (#8204) - Inherited JWT default permissions are now refreshed when account claims are updated (#8276) - External auth configuration is now cleared correctly when account claims are updated (#8275) - PROXY protocol detection, TLS sniffing with `allow_non_tls` and PROXY v1 address-family parsing have been fixed (#8302) - A race in gateway `CONNECT` handling has been fixed (#8306) - Trusted proxy tracking no longer leaks closed clients during concurrent updates (#8307) - Service import replies can now be delivered across cluster routes (#8317) - Message tracing now works correctly with service imports and exports - Several panic, fatal and data race conditions in authentication, routing, monitoring and clustered request handling have been fixed - `NoAuthUser` now checks connection restrictions - Leaf connections no longer bypass `Nats-Trace-Dest` publish permission checks - `CONNZ` and `SUBSZ` pagination now guard against `Offset` and `Limit` integer overflow panics - Fixed a nil pointer panic when starting up when the resolver parent directory is missing (#8329) MQTT - Partial `CONNECT` packets can no longer exhaust pre-authentication memory - `PUBLISH` remaining-length underflow no longer causes a server panic - Subscriptions to internal `$MQTT.deliver.pubrel` subjects are now rejected - Subscribe deny rules are now enforced on retained message and QoS replay paths - WebSocket `/mqtt` upgrades no longer panic when MQTT is disabled Monitoring - JetStream remote usage updates no longer panic on length integer overflow JetStream - A data race on the cluster meta node during JetStream shutdown has been fixed (#8260) - Meta proposal inflight tracking is now kept consistent during stream moves and related operations (#8261) - Stream catchup is no longer skipped when limits are exceeded, preventing possible stream desync (#8265) - Malformed TTL and schedule state is now rejected during decode (#8269) - Zero consumer limits are now treated as unlimited during stream updates (#8286) - Raft nodes no longer participate in voting or candidacy after write errors (#8290) - Raft checkpoint handling now aborts if the node is closed (#8296) - Raft `ApplyCommit` now handles the post-snapshot index correctly (#8321) - Consumer ack subscriptions now match correctly when consumer names contain `%` (#8301) - Observer state is now cleared correctly during `js_cluster_migrate` when a leaf remote is removed (#8304) - Atomic batch end-of-batch max-size checks and R1 message rewrites have been fixed (#8305) - Schedule drift, failed fast batch commits with `gapOk` and stale `/varz` leaf remote state have been fixed (#8308) - Peer state decoding now bounds peer ID reads to the buffer length (#8310) - Counter stream staging no longer corrupts the committed running total (#8311) _[Truncated at 4000 characters — full notes: https://github.com/nats-io/nats-server/releases/tag/v2.14.3]_ ### v2.12.12 — Release v2.12.12 - Date: 2026-06-29 - Version: v2.12.12 - Original notes: https://github.com/nats-io/nats-server/releases/tag/v2.12.12 - Permalink: https://whatsnew.fyi/product/nats/releases/v2.12.12 - **changed** — Per-connection log lines that could be noisy in normal operation have been demoted to debug level - **changed** — Writer options are now applied consistently when using the s2_fast compression mode - **changed** — Stream and consumer assignment handling has been refactored for more consistent migration and info behavior - **changed** — Meta, stream and consumer write errors are now registered more consistently for health and recovery handling - **removed** — JSONP callback support has been removed from monitoring endpoints - **fixed** — Inherited JWT default permissions are now refreshed when account claims are updated - **fixed** — External auth configuration is now cleared correctly when account claims are updated - **fixed** — PROXY protocol detection, TLS sniffing with allow_non_tls and PROXY v1 address-family parsing have been fixed - **fixed** — A race in gateway CONNECT handling has been fixed - **fixed** — Trusted proxy tracking no longer leaks closed clients during concurrent updates - **fixed** — Service import replies can now be delivered across cluster routes - **fixed** — Message tracing now works correctly with service imports and exports - **fixed** — Several panic, fatal and data race conditions in authentication, routing, monitoring and clustered request handling have been fixed - **fixed** — NoAuthUser now checks connection restrictions - **fixed** — CONNZ and SUBSZ pagination now guard against Offset and Limit integer overflow panics - **fixed** — Fixed a nil pointer panic when starting up when the resolver parent directory is missing - **fixed** — Partial CONNECT packets can no longer exhaust pre-authentication memory - **fixed** — PUBLISH remaining-length underflow no longer causes a server panic - **fixed** — Subscriptions to internal $MQTT.deliver.pubrel subjects are now rejected - **fixed** — Subscribe deny rules are now enforced on retained message and QoS replay paths ##### Changelog ###### Go Version - 1.25.11 ###### Dependencies - golang.org/x/crypto v0.53.0 (#8297) - golang.org/x/sys v0.46.0 (#8297) - github.com/nats-io/jwt/v2 v2.8.2 - github.com/nats-io/nkeys v0.4.16 ###### Improved General - Per-connection log lines that could be noisy in normal operation have been demoted to debug level (#8289) - Writer options are now applied consistently when using the `s2_fast` compression mode (#8047) JetStream - Stream and consumer assignment handling has been refactored for more consistent migration and info behavior (#8262) - Meta, stream and consumer write errors are now registered more consistently for health and recovery handling (#8293) ###### Removed Monitoring - JSONP callback support has been removed from monitoring endpoints ###### Fixed General - Inherited JWT default permissions are now refreshed when account claims are updated (#8276) - External auth configuration is now cleared correctly when account claims are updated (#8275) - PROXY protocol detection, TLS sniffing with `allow_non_tls` and PROXY v1 address-family parsing have been fixed (#8302) - A race in gateway `CONNECT` handling has been fixed (#8306) - Trusted proxy tracking no longer leaks closed clients during concurrent updates (#8307) - Service import replies can now be delivered across cluster routes (#8317) - Message tracing now works correctly with service imports and exports - Several panic, fatal and data race conditions in authentication, routing, monitoring and clustered request handling have been fixed - `NoAuthUser` now checks connection restrictions - `CONNZ` and `SUBSZ` pagination now guard against `Offset` and `Limit` integer overflow panics - Fixed a nil pointer panic when starting up when the resolver parent directory is missing (#8329) MQTT - Partial `CONNECT` packets can no longer exhaust pre-authentication memory - `PUBLISH` remaining-length underflow no longer causes a server panic - Subscriptions to internal `$MQTT.deliver.pubrel` subjects are now rejected - Subscribe deny rules are now enforced on retained message and QoS replay paths - WebSocket `/mqtt` upgrades no longer panic when MQTT is disabled Monitoring - JetStream remote usage updates no longer panic on length integer overflow JetStream - A data race on the cluster meta node during JetStream shutdown has been fixed (#8260) - Meta proposal inflight tracking is now kept consistent during stream moves and related operations (#8261) - Stream catchup is no longer skipped when limits are exceeded, preventing possible stream desync (#8265) - Malformed TTL and schedule state is now rejected during decode (#8269) - Zero consumer limits are now treated as unlimited during stream updates (#8286) - Raft nodes no longer participate in voting or candidacy after write errors (#8290) - Raft checkpoint handling now aborts if the node is closed (#8296) - Raft `ApplyCommit` now handles the post-snapshot index correctly (#8321) - Consumer ack subscriptions now match correctly when consumer names contain `%` (#8301) - Atomic batch end-of-batch max-size checks and R1 message rewrites have been fixed (#8305) - Peer state decoding now bounds peer ID reads to the buffer length (#8310) - Counter stream staging no longer corrupts the committed running total (#8311) - Filestore compaction no longer corrupts compressed or encrypted blocks (#8312) - Memory store `NumPending` no longer overcounts for `DeliverLastPerSubject` consumers (#8313) - Consumer inactive-delete grace period handling and pull request `MaxBytes` budgeting have been fixed (#8314) - `MultiLastSeqs` no longer reorders stream config subjects through `filterIsAll` handling (#8315) - Meta recovery snapshots no longer leave phantom streams or consumers behind (#8324) - Skipped messages last time no longer violates ordering that could lead to issues with starting by time (#8237) - Raft now reverts uncommitted me _[Truncated at 4000 characters — full notes: https://github.com/nats-io/nats-server/releases/tag/v2.12.12]_ ### v2.12.11 — Release v2.12.11 - Date: 2026-06-09 - Version: v2.12.11 - Original notes: https://github.com/nats-io/nats-server/releases/tag/v2.12.11 - Permalink: https://whatsnew.fyi/product/nats/releases/v2.12.11 - **fixed** — Fixed a regression introduced in v2.12.7 which could result in stale subject state tracking which could manifest in "Message Not Found" errors when a max messages per subject limit is configured ##### Changelog Refer to the [2.12 Upgrade Guide](https://docs.nats.io/release-notes/whats_new/whats_new_212) for backwards compatibility notes with 2.11.x. ###### Go Version - 1.25.11 ###### Fixed JetStream - Fixed a regression introduced in v2.12.7 which could result in stale subject state tracking which could manifest in "Message Not Found" errors when a max messages per subject limit is configured (#8285) - Please note that v2.14.x versions are not affected ###### Complete Changes https://github.com/nats-io/nats-server/compare/v2.12.10...v2.12.11 ### v2.14.2 — Release v2.14.2 - Date: 2026-06-02 - Version: v2.14.2 - Original notes: https://github.com/nats-io/nats-server/releases/tag/v2.14.2 - Permalink: https://whatsnew.fyi/product/nats/releases/v2.14.2 - **changed** — Client ID is now available through the embedded ClientAuthentication API - **fixed** — Fixed a race condition when handling subscription interest over routes - **fixed** — Fixed potential protocol-level corruption from rewriting $JS.ACK subjects - **fixed** — Fixed potential protocol-level corruption from buffer misuse in compressed WebSocket clients - **fixed** — The /accstatz monitoring endpoint no longer omits accounts with only leaf connections - **fixed** — Fixed a case where Raft peers were not correctly tracked after an inactivity stall during catchup - **fixed** — Quorum needed is now calculated correctly when bootstrapping the metalayer when gateway URLs resolve to multiple IP addresses - **fixed** — The filestore no longer performs a block skip check on streams with extremely high subject counts that could result in runaway CPU usage - **fixed** — Fixed a case where the filestore would not release a lock after handling a write error - **fixed** — Purge operations on both file and memory stores are now more consistent with each other - **fixed** — Fixed a case where the consumer lock would not release a lock after handling a start sequence error - **fixed** — Counter streams and message schedules now have configuration constraints applied to prevent incorrect usage patterns - **fixed** — Improved stream and consumer scale down behaviour consistency - **fixed** — Fixed an issue where the per-subject state last block was not stored correctly with a max messages per subject limit of 1 - **fixed** — Fixed a drift that could occur in the peer sets after a peer remove of an online node ##### Changelog Refer to the [2.14 Upgrade Guide](https://docs.nats.io/release-notes/whats_new/whats_new_214) for backwards compatibility notes with 2.12.x. Please note that the 2.13.x version was skipped. ###### Go Version - 1.26.3 ###### Dependencies - golang.org/x/crypto v0.52.0 - golang.org/x/sys v0.45.0 - github.com/nats-io/jwt/v2 v2.8.2 - github.com/nats-io/nkeys v0.4.16 ###### Improved General - The client ID is now available through the embedded `ClientAuthentication` API (#8217) ###### Fixed General - A race condition when handling subscription interest over routes has been fixed (#8235) - Potential protocol-level corruption from rewriting `$JS.ACK` subjects has been fixed (#8242) - Potential protocol-level corruption from buffer misuse in compressed WebSocket clients has been fixed (#8244) - The `/accstatz` monitoring endpoint no longer omits accounts with only leaf connections (#8252) JetStream - Fixed a case where Raft peers were not correctly tracked after an inactivity stall during catchup (#8226) - Quorum needed is now calculated correctly when bootstrapping the metalayer when gateway URLs resolve to multiple IP addresses (#8238) - The filestore no longer performs a block skip check on streams with extremely high subject counts, as it could result in runaway CPU usage (#8227) - Fixed a case where the filestore would not release a lock after handling a write error (#8232) - Purge operations on both file and memory stores are now more consistent with each other (#8241) - Fixed a case where the consumer lock would not release a lock after handling a start sequence error (#8230) - Counter streams and message schedules now have configuration constraints applied to prevent incorrect usage patterns (#8240) - Improved stream and consumer scale down behaviour consistency (#8253) - Fixed an issue where the per-subject state last block was not stored correctly with a max messages per subject limit of 1 (#8254) - Fixed a drift that could occur in the peer sets after a peer remove of an online node (#8258) ###### Complete Changes https://github.com/nats-io/nats-server/compare/v2.14.1...v2.14.2 ### v2.12.10 — Release v2.12.10 - Date: 2026-06-02 - Version: v2.12.10 - Original notes: https://github.com/nats-io/nats-server/releases/tag/v2.12.10 - Permalink: https://whatsnew.fyi/product/nats/releases/v2.12.10 - **added** — The client ID is now available through the embedded ClientAuthentication API - **fixed** — A race condition when handling subscription interest over routes has been fixed - **fixed** — Potential protocol-level corruption from rewriting $JS.ACK subjects has been fixed - **fixed** — Potential protocol-level corruption from buffer misuse in compressed WebSocket clients has been fixed - **fixed** — The /accstatz monitoring endpoint no longer omits accounts with only leaf connections - **fixed** — Fixed a case where Raft peers were not correctly tracked after an inactivity stall during catchup - **fixed** — Quorum needed is now calculated correctly when bootstrapping the metalayer when gateway URLs resolve to multiple IP addresses - **fixed** — The filestore no longer performs a block skip check on streams with extremely high subject counts, as it could result in runaway CPU usage - **fixed** — Purge operations on both file and memory stores are now more consistent with each other - **fixed** — Counter streams and message schedules now have configuration constraints applied to prevent incorrect usage patterns - **changed** — Improved stream and consumer scale down behaviour consistency - **fixed** — Fixed an issue where the per-subject state last block was not stored correctly with a max messages per subject limit of 1 - **fixed** — Fixed a drift that could occur in the peer sets after a peer remove of an online node ##### Changelog Refer to the [2.12 Upgrade Guide](https://docs.nats.io/release-notes/whats_new/whats_new_212) for backwards compatibility notes with 2.11.x. ###### Go Version - 1.25.10 ###### Dependencies - golang.org/x/crypto v0.52.0 - golang.org/x/sys v0.45.0 - github.com/nats-io/jwt/v2 v2.8.2 - github.com/nats-io/nkeys v0.4.16 ###### Improved General - The client ID is now available through the embedded `ClientAuthentication` API (#8217) ###### Fixed General - A race condition when handling subscription interest over routes has been fixed (#8235) - Potential protocol-level corruption from rewriting `$JS.ACK` subjects has been fixed (#8242) - Potential protocol-level corruption from buffer misuse in compressed WebSocket clients has been fixed (#8244) - The `/accstatz` monitoring endpoint no longer omits accounts with only leaf connections (#8252) JetStream - Fixed a case where Raft peers were not correctly tracked after an inactivity stall during catchup (#8226) - Quorum needed is now calculated correctly when bootstrapping the metalayer when gateway URLs resolve to multiple IP addresses (#8238) - The filestore no longer performs a block skip check on streams with extremely high subject counts, as it could result in runaway CPU usage (#8227) - Purge operations on both file and memory stores are now more consistent with each other (#8241) - Counter streams and message schedules now have configuration constraints applied to prevent incorrect usage patterns (#8240) - Improved stream and consumer scale down behaviour consistency (#8253) - Fixed an issue where the per-subject state last block was not stored correctly with a max messages per subject limit of 1 (#8254) - Fixed a drift that could occur in the peer sets after a peer remove of an online node (#8258) ###### Complete Changes https://github.com/nats-io/nats-server/compare/v2.12.9...v2.12.10 ### v2.14.2-RC.1 — Release v2.14.2-RC.1 - Date: 2026-05-29 - Version: v2.14.2-RC.1 - Original notes: https://github.com/nats-io/nats-server/releases/tag/v2.14.2-RC.1 - Permalink: https://whatsnew.fyi/product/nats/releases/v2.14.2-rc.1 - Labels: Pre-release - **fixed** — Fix a race condition when handling subscription interest over routes - **fixed** — Fix potential protocol-level corruption from rewriting $JS.ACK subjects - **fixed** — Fix potential protocol-level corruption from buffer misuse in compressed WebSocket clients - **fixed** — Fix a case where Raft peers were not correctly tracked after an inactivity stall during catchup - **fixed** — Fix quorum calculation when bootstrapping the metalayer when gateway URLs resolve to multiple IP addresses - **fixed** — Remove block skip check on streams with extremely high subject counts in filestore to prevent runaway CPU usage - **fixed** — Fix a case where the filestore would not release a lock after handling a write error - **fixed** — Make purge operations on both file and memory stores more consistent with each other - **fixed** — Fix a case where the consumer lock would not release a lock after handling a start sequence error - **fixed** — Apply configuration constraints to counter streams and message schedules to prevent incorrect usage patterns ##### Changelog Refer to the [2.14 Upgrade Guide](https://docs.nats.io/release-notes/whats_new/whats_new_214) for backwards compatibility notes with 2.12.x. Please note that the 2.13.x version was skipped. ###### Go Version - 1.26.3 ###### Dependencies - golang.org/x/crypto v0.52.0 - golang.org/x/sys v0.45.0 ###### Fixed General - A race condition when handling subscription interest over routes has been fixed (#8235) - Potential protocol-level corruption from rewriting `$JS.ACK` subjects has been fixed (#8242) - Potential protocol-level corruption from buffer misuse in compressed WebSocket clients has been fixed (#8244) JetStream - Fixed a case where Raft peers were not correctly tracked after an inactivity stall during catchup (#8226) - Quorum needed is now calculated correctly when bootstrapping the metalayer when gateway URLs resolve to multiple IP addresses (#8238) - The filestore no longer performs a block skip check on streams with extremely high subject counts, as it could result in runaway CPU usage (#8227) - Fixed a case where the filestore would not release a lock after handling a write error (#8232) - Purge operations on both file and memory stores are now more consistent with each other (#8241) - Fixed a case where the consumer lock would not release a lock after handling a start sequence error (#8230) - Counter streams and message schedules now have configuration constraints applied to prevent incorrect usage patterns (#8240) ###### Complete Changes https://github.com/nats-io/nats-server/compare/v2.14.1...v2.14.2-RC.1 ### v2.12.10-RC.1 — Release v2.12.10-RC.1 - Date: 2026-05-29 - Version: v2.12.10-RC.1 - Original notes: https://github.com/nats-io/nats-server/releases/tag/v2.12.10-RC.1 - Permalink: https://whatsnew.fyi/product/nats/releases/v2.12.10-rc.1 - Labels: Pre-release - **fixed** — Fix a race condition when handling subscription interest over routes - **fixed** — Fix potential protocol-level corruption from rewriting $JS.ACK subjects - **fixed** — Fix potential protocol-level corruption from buffer misuse in compressed WebSocket clients - **fixed** — Fix a case where Raft peers were not correctly tracked after an inactivity stall during catchup - **fixed** — Fix quorum needed calculation when bootstrapping the metalayer when gateway URLs resolve to multiple IP addresses - **fixed** — Remove block skip check on streams with extremely high subject counts in the filestore to prevent runaway CPU usage - **fixed** — Make purge operations on both file and memory stores more consistent with each other - **fixed** — Apply configuration constraints to counter streams and message schedules to prevent incorrect usage patterns ##### Changelog Refer to the [2.12 Upgrade Guide](https://docs.nats.io/release-notes/whats_new/whats_new_212) for backwards compatibility notes with 2.11.x. ###### Go Version - 1.25.10 ###### Dependencies - golang.org/x/crypto v0.52.0 - golang.org/x/sys v0.45.0 ###### Fixed General - A race condition when handling subscription interest over routes has been fixed (#8235) - Potential protocol-level corruption from rewriting `$JS.ACK` subjects has been fixed (#8242) - Potential protocol-level corruption from buffer misuse in compressed WebSocket clients has been fixed (#8244) JetStream - Fixed a case where Raft peers were not correctly tracked after an inactivity stall during catchup (#8226) - Quorum needed is now calculated correctly when bootstrapping the metalayer when gateway URLs resolve to multiple IP addresses (#8238) - The filestore no longer performs a block skip check on streams with extremely high subject counts, as it could result in runaway CPU usage (#8227) - Purge operations on both file and memory stores are now more consistent with each other (#8241) - Counter streams and message schedules now have configuration constraints applied to prevent incorrect usage patterns (#8240) ###### Complete Changes https://github.com/nats-io/nats-server/compare/v2.12.9...v2.12.10-RC.1 ### v2.14.1 — Release v2.14.1 - Date: 2026-05-20 - Version: v2.14.1 - Original notes: https://github.com/nats-io/nats-server/releases/tag/v2.14.1 - Permalink: https://whatsnew.fyi/product/nats/releases/v2.14.1 - **added** — New metrics in_client_msgs, in_client_bytes, out_client_msgs and out_client_bytes are now available via the /varz monitoring endpoint for tracking data to/from normal clients only - **changed** — Client TLS certificates without subject DNs but with DNS subject alternate names are now permitted - **changed** — The log level of TLS handshake timeout or non-TLS record errors have been demoted to debug level to reduce noise - **changed** — Num pending is now only calculated on consumer leaders, avoiding unnecessary CPU usage on followers - **fixed** — Cluster route compression now obeys the cluster max_pings_out option if configured - **fixed** — The internal send loop no longer mutates caller headers, which could corrupt buffers - **fixed** — Removing headers no longer fails to remove later headers if the matching prefix also appeared in an earlier header value - **fixed** — The sublist now correctly maintains negative results in the cache when calculating number of interested subjects - **fixed** — Server shutdown requests are now idempotent, preventing concurrency issues when shutting down in embedded contexts - **fixed** — TLS listeners now work correctly with the PROXY protocol where enabled - **fixed** — Reduced lock contention that could be created between leafnodes and clients - **fixed** — Fixed a panic that could happen when an error occurs when walking JWT directory resolver folders - **fixed** — In-process connections will no longer unexpectedly revert to TLS required with async INFO - **fixed** — Snapshot and catchup loops no longer leak timers - **fixed** — Stream and consumer assignment errors are now surfaced - **fixed** — Intersection of sublists and subject trees can now be cancelled early, avoiding high CPU usage in some pathological cases - **fixed** — Leafnode connections will no longer negotiate compression if they are configured over already-compressed WebSockets - **fixed** — Fast batch now correctly parses the batch sequence as a uint64 - **fixed** — Atomic batch no longer double-pools committed entries on cleanup ##### Changelog Refer to the [2.14 Upgrade Guide](https://docs.nats.io/release-notes/whats_new/whats_new_214) for backwards compatibility notes with 2.12.x. Please note that the 2.13.x version was skipped. ###### Go Version - 1.26.3 (#8107) ###### Dependencies - github.com/klauspost/compress v1.18.6 (#8124) - golang.org/x/crypto v0.51.0 (#8124) - golang.org/x/sys v0.44.0 (#8124) ###### Added General - New metrics `in_client_msgs`, `in_client_bytes`, `out_client_msgs` and `out_client_bytes` are now available via the `/varz` monitoring endpoint for tracking data to/from normal clients only (#7851) ###### Improved General - Client TLS certificates without subject DNs but with DNS subject alternate names are now permitted (#8100) - The log level of TLS handshake timeout or non-TLS record errors have been demoted to debug level to reduce noise (#8096) JetStream - Num pending is now only calculated on consumer leaders, avoiding unnecessary CPU usage on followers (#8172) - Snapshot and catchup loops no longer leak timers (#8186, thanks to @SebTardif) - Stream and consumer assignment errors are now surfaced (#8208) - Intersection of sublists and subject trees can now be cancelled early, avoiding high CPU usage in some pathological cases (#8209) ###### Fixed General - Cluster route compression now obeys the cluster `max_pings_out` option if configured (#8093) - The internal send loop no longer mutates caller headers, which could corrupt buffers (#8097) - Removing headers no longer fails to remove later headers if the matching prefix also appeared in an earlier header value (#8103) - The sublist now correctly maintains negative results in the cache when calculating number of interested subjects (#8119) - Server shutdown requests are now idempotent, preventing concurrency issues when shutting down in embedded contexts (#8163) - TLS listeners now work correctly with the PROXY protocol where enabled (#8130) - Reduced lock contention that could be created between leafnodes and clients (#8139, #8159) - Fixed a panic that could happen when an error occurs when walking JWT directory resolver folders (#8173, thanks to @SebTardif) - In-process connections will no longer unexpectedly revert to TLS required with async `INFO` (#8205) Leafnodes - Leafnode connections will no longer negotiate compression if they are configured over already-compressed WebSockets (#7969) JetStream - Fast batch now correctly parses the batch sequence as a uint64 (#8094) - Atomic batch no longer double-pools committed entries on cleanup (#8098) - Raft nodes will now ignore temporary snapshots on recovery after a crash (#8101) - A number of paths that could leave consumer redelivered in a drifted state have been fixed, e.g. with workqueue or interest-based streams with `max_deliver`, on single message removal or after purges/compactions (#8102) - Caches are now cleared correctly when converting filestore encryption mode, avoiding block-level corruption (#8105, #8166) - Fixed a race condition when updating the deduplication map on leader change (#8106) - Source consumer creation will no longer schedule a recreation if a setup is already in progress, avoiding potential setup storms (#8111) - Fixed data races when reading from the stream configuration when checking reservations, answering some API requests amongst others (#8115) - Stream republish subjects are now validated correctly (#8127) - The delivery policy for consumers on clustered workqueue streams is now enforced correctly (#8126) - The `Nats-Schedule-Next: purge` action now correctly checks if the target is a schedule (#8135) - Raft node append entry caches are now invalidated correctly on WAL truncation and snapshot installs (#8149) - Skip message errors are now surfaced correctly, propagating failures (#8152) - Mirror consumers are now retried immediately on a last sequence mismatch, avoiding stalling for longer than necessary _[Truncated at 4000 characters — full notes: https://github.com/nats-io/nats-server/releases/tag/v2.14.1]_