Last 7 days
0
Features: 0
Changes: 0
Fixes: 0
Deprecations: 0
Cloud-native messaging system for services, streams, and event-driven systems.
Latest NATS changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this NATS release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
0
4
9
29
Added Leafnodes support with a configurable dial timeout option for high‑latency links
Upgrade to Go 1.25.12 and bump critical dependencies (klauspost/compress v1.19.2, golang.org/x/crypto v0.55.0).
Decoupled Raft transport and increased disk concurrency (now configurable) with several JetStream performance and memory optimizations;
Decoupled JetStream Raft transport and increased disk concurrency semaphore to 4096 (configurable via max_concurrent_io) to improve performance and memory handling;
Fixed numerous bugs and race conditions across authentication, routing, monitoring, JetStream, Raft, and MQTT, preventing panics, memory leaks, and stream desynchronisation.
Fixed numerous race conditions, panics, and data‑race issues across authentication, routing, monitoring, JetStream, and Raft, improving stability and security.
Updated Go runtime to version 1.25.11.
Fixed race condition in subscription interest handling and multiple protocol corruption issues
Expose client ID through the embedded ClientAuthentication API
Added new client traffic metrics to the /varz endpoint and allowed TLS certificates with DNS SANs without subject DNs.
Added new client traffic metrics (client msgs/bytes in/out) to the /varz endpoint.
Added numerous JetStream enhancements, including fast ingest batch publishing, atomic batch commit, consumer reset API, scheduled message support, async stream snapshots, and new feature‑flag configuration.
Refactored JetStream consumer header handling, made start‑sequence scanning asynchronous, added leafnode connect advisory, and improved stream leader catch‑up and roll‑up behavior.
Fixed several security-related issues: gateway pinned cert reload, /connz endpoint no longer exposes bearer JWTs, and command‑line URL secrets are redacted.
- JetStream performance upgrades: purging now loads only relevant filestore blocks, optimized filtered load paths, max mem/file store limits can be raised via config reload, stream leaders can catch up from snapshots, and consumer max‑ac...
Enforced correct ACL behavior: overlapping wildcard deny patterns, leafnode inbound messages, and payload limits are now properly applied.
Fixes multiple CVEs spanning MQTT, leafnodes, WebSockets, JetStream, TLS, and credential handling, improving overall security.
Fixed numerous CVE‑related security issues, added a 1 MB JWT size limit, and ensured secrets and MQTT passwords are redacted in logs and endpoints.
Regression in clustered deployments may lose stream consumers; mitigated by setting `meta compact sync: true` and will be fixed in v2.12.6.
Fixed CVE‑2026‑29785 and CVE‑2026‑27889 affecting leafnode compression and WebSockets
Added TLS certificate expiry information to the varz monitoring endpoint.
Added configurable WebSocket ping interval and TLS certificate expiry info to the monitoring endpoint.
Added configurable WebSocket ping interval and improved MQTT retained message handling and payload limits.
Added support for PROXY protocol (v1/v2) on client connections and introduced write timeout options for clients, routes, gateways, and leafnodes.
Added JetStream enhancements: meta compact settings, write timeout options, expanded /jsz monitoring (leader counts, direct consumers) and parallel stream loading.
Added NewServerFromConfig API for loading external configs and enabled WebSocket leafnode connections to use HTTP proxies with configurable write deadlines.
Improved JetStream and filestore performance: faster TTL handling, reduced lock contention, binary search for timestamp lookups, and fewer heap allocations.
Added extensive JetStream enhancements (atomic batch publishes, counter streams, prioritized consumer groups, delayed scheduling, async writes, strict API v2 mode, offline asset handling, and replica stream improvements).
- Added JetStream offline assets support, allowing safe downgrade by marking streams/consumers as offline and preserving data.
Add community‑contributed build support for Solaris and Illumos.
Exported SubjectMatchesFilter function for embedded use and added connection ID and endpoint name hover to monitoring UI.
Improved JetStream source handling (no timestamp updates when stalled) and overall consumer performance with reduced allocations and better pending calculation
Added leafnode connection stats to connz and expanded accstatsz to include leafnode, route, and gateway metrics, improving monitoring capabilities.
Fixed multiple bugs causing panics, deadlocks, and incorrect sequence handling in JetStream streams/consumers, and prevented goroutine leaks
Added MQTT JavaScript API timeout option for JetStream operations.
Fixed JetStream regression in consumer subject interest calculation and improved consistency of filtered consumer state reporting.
Added default sentinel JWT for operator mode, new trace‑only‑headers option, and support for importing the same subject from multiple accounts and differing pool sizes across routes.
Added support for importing the same subject from multiple accounts via service imports and improved publish permissions cache pruning
Fix critical CVE-2025-30215 affecting all NATS Server versions.
Patched critical CVE‑2025‑30215 affecting all NATS Server versions prior to v2.11.1/v2.10.27.
Critical CVE-2025-30215 vulnerability fixed in binary release
Fix critical CVE‑2025‑30215 affecting all NATS Server versions prior to v2.11.1 or v2.10.27.
Added extensive JetStream enhancements: per‑message TTLs, subject delete markers, priority consumer groups with pinning/overflow, consumer pause/resume, pedantic mode, ingest rate limiting, and strict API decoding.
Added new server options (no fast producer stall, first info timeout) and expanded monitoring endpoints (gatewayz, raftz, ipqueuesz, routez) with extra subscription and pending bytes data.
Optimized JetStream Raft group snapshot handling and removed stream snapshot interval, boosting performance and reducing lock contention.
Addressed CVE‑2024‑45337 by updating golang.org/x/crypto and upgraded Go to 1.23.4 (security).
Added JetStream support for forwarded proposals and introduced several performance enhancements across consumers, Raft, and metalayer snapshot handling
Added a startup warning for JetStream store directories in temporary locations and improved search efficiency for subscription sublists.
Add a configurable minimum TLS version setting
Fixed JetStream regression affecting KV CAS operations on single-replica (R=1) configurations introduced in v2.10.19.
Added StreamLeaderOnly filter for monitoring and enabled CPU profile retrieval via the profilez endpoint.
Added support for initiating lame‑duck mode in the embedded export server when embedding NATS
Introduced an experimental /raftz monitoring endpoint for Raft diagnostics and optimized core memory alignment using stree structures.
Fixed a startup panic regression caused by zero‑byte `tav.idx` files; users can delete those files as a workaround.
Added constant‑time evaluation for non‑bcrypt passwords and hardened authentication handling (security).
Fixed multiple stability issues including a panic on 32‑bit queue subscription randomisation, a memory leak during compaction, and race conditions in Raft and OCSP handling
Upgrade to Go 1.20.14.
Optimized JetStream replay for end‑of‑stream and large gap scenarios, improving performance and reducing contention during NRG step‑down.
Add configurable ping interval for cluster routes and upgrade to Go 1.21.6
Added reference to the 2.10 Upgrade Guide for backward‑compatibility notes with 2.9.x.
Added TLS 'certs' option for multi‑certificate support and enabled nkey authentication for leafnodes and no‑auth users.
Increased minimum interval for full index.db state writes, reducing contention during high‑speed ingest in large JetStream streams.
Added JetStream filestore state checks, memory reductions, subject filter optimizations, and pre‑check for last‑subject header; plus fixes for discard‑old policy and consumer updates
Reduced GC pressure and memory usage by eliminating time.After patterns, optimizing filestore scans, and improving state allocation estimation.
Added stricter JetStream Raft state management to improve recovery from leaderless states
Security: Fixed CVE‑2023‑46129 by correcting nkeys seal encryption and updated Go to 1.21.3.
Fixed JetStream space reclamation during compaction with compression enabled
Fix authorization bypass when enabling system account access in the accounts block.
Changed on-disk storage format for significant performance gains; downgrades below 2.9.22 cannot read the new format.
Added compatibility note: downgrading from 2.10.x to versions earlier than 2.9.22 will fail to read the new on‑disk storage format.
Introduced a new on‑disk storage format with significant performance gains; downgrades only work back to v2.9.22+ to read streams correctly.
- Updated to Go 1.20.8 and refreshed core dependencies (NATS JWT, crypto, sys).
Added OCSP fetch, cache, and verification for client and leaf mTLS connections and removed the requirement that all super‑cluster peers share the same CA (security);
Added native Windows certificate store support (with Go 1.19.11 backport) and enabled export/import of account advisories.
Updated Go runtime to version 1.19.10.
Upgrade to Go 1.19.10 and update core dependencies (golang.org/x/crypto, golang.org/x/sys, nats.io/nats.go).
Added performance optimizations across core queues, leafnode subscription propagation, WebSocket compression, Raft leadership, and JetStream snapshot handling, reducing memory footprint and latency.
Added nightly Docker image (synadia/nats-server:nightly) and embedded build SHA in Goreleaser releases.
Added monitoring endpoints, a raft query parameter for /jsz, and enhanced /leafz with server name and spoke flag.
Upgrade to Go 1.19.5 for release binaries and Docker images.
Added DragonFly BSD support and upgraded build to Go 1.19.5 across executables and Docker images.
Upgrade build environment to Go 1.19.4 and bump golang.org/x/crypto to v0.5.0.
Upgrade server and Docker builds to Go 1.19.4.
Upgrade build to Go 1.19.4 and add two new reload signal options (ldm, term) to help/usage.
Upgrade builds to Go 1.19.3 for executables and Docker images.
JetStream performance upgrades: improved ack processing, faster ingest with many consumers, and StreamDetail now reports creation time on /healthz.
Fixed JetStream panic when a consumer monitor started after the consumer was deleted or scaled down.
Upgrade build to Go 1.19.3 for executables and Docker images
Fixed multiple JetStream consumer and RAFT issues (deadlock, ghost consumers, inactive threshold handling, replica changes, memory leak) and added pending messages/bytes info to pull request errors.
Fixed JetStream unresponsiveness during RAFT group creation on slow disks and addressed purge option edge cases.
Restored fan‑out performance to pre‑v2.8.4 levels after regression.
Updated build to Go 1.19.1 and refreshed dependencies.
Added extensive JetStream enhancements such as AllowDirect API, MirrorDirect, InactiveThreshold for durables, stream move support, filter subjects, consumer replica changes, AES‑GCM encryption for FileStore, catch‑up bandwidth limits, pa...
Updated binaries and Docker images to build with Go 1.17.10.
Added JetStream consumer options (MaxRequestMaxBytes, explicit replica count, memory storage) and experimental Stream RePublish mapping
Added JetStream JSConsumerDeliveryNakAdvisory and support for subject transforms/delivery subjects.
Updated Go build to 1.17.9 and bumped crypto dependency to address a CVE (security update).
JetStream receives major upgrades: beta support for migrating streams/consumers across clusters, a unique tag to prevent same‑AZ placement, Stream Alternates metadata, deterministic subject token mapping, healthz consumer checks, max‑str...
Updated Go version and packaging defaults; .deb/.rpm now install to /usr/bin (breaking change for install scripts).
Added JetStream enhancements: replica updates during stream updates, stream placement by tags, and sparse consumer replay optimizations.
Updated server build to Go 1.17.6 and added JetStream per‑subject details in StreamInfo (NumSubjects and optional Subjects list).
Upgrade to Go 1.17.6 and add JetStream enhancements: delayed NAK, consumer backoff list, replication‑lag metrics, and reworked pull consumers.
Added extensive JetStream enhancements: configurable account limits, overflow stream placement, support for ephemeral pull consumers, new consumer options, max store size strings, JWT MaxBytesRequired, MQTT over WebSocket, TLS connection...
Added support for Leafnode over WebSocket via a new allowed connection type and fixed related restrictions.
Added new server option AlwaysEnableNonce to always include a nonce in the INFO block (useful for embedded scenarios).
Added ability for system account to indicate JetStream not enabled, improving CLI interactions.
Fixed multiple JetStream and cluster bugs including purge count, panic on unlocked RWMutex, stream sealing flags, and consumer redelivery decoding
Added new JetStream capabilities: stream sealing, roll‑up support, header‑only consumer delivery, and configuration limits for delete/purge/roll‑ups.
Fixed JetStream deadlock with stream mirrors using non‑limit retention and corrected memory leak
Added JetStream monitoring of reserved and used memory via /jsz and /varz endpoints and hardened systemd service.
Added MQTT monitoring and unified MQTT session storage into a single stream, reducing resource usage
Fixed JetStream queue subscription behavior by adding PushBound and DeliverGroup fields, now returning errors for duplicate or invalid queue subscriptions and enforcing proper queue groups.
Server now rejects max payload settings higher than max pending and warns when above 8 MB (future enforcement).
Added ReloadOptions API for config reload without files and introduced Kind/ClientType for CONNECT/DISCONNECT events.
Updated Go to 1.16.5 and rebuilt all executables and Docker images.
Added JetStream capabilities: retrieve a stream's last message by subject, match on last expected sequence per subject, and support large numbers of R1 consumers per stream.
Added extensive JetStream enhancements including error codes, per‑subject limits, advanced purge requests, encryption at rest and OCSP support.
Improved security: pinned certificates are now validated on outbound connections and stale certs trigger connection closures.
Bumped Go to 1.16.4 and rebuilt all executables and Docker images.
Updated to Go 1.16.4 and rebuilt server binaries/Docker images.
Fix security issue where TLS default ciphers were not applied when configuring via CLI (CVE‑2021‑32026).
Added Kind() method to ClientAuthentication interface for connection type detection (feature).
Added configurable timeout for the NATS resolver and switched JetStreamVarz fields to pointers, which may affect embedded server usage
Introduced JetStream persistence, WebSocket and MQTT support with new authentication methods and added several monitoring endpoints (jsz, accountz, tag‑filtered PING, etc.)
Fixed security vulnerabilities (CVE‑2020‑26521 JWT panic and CVE‑2020‑26892 revocation checks)
Updated Go version to 1.14.8 for server binaries and Docker images.
Added monitoring endpoints (including /subsz) with configurable HTTP base path and support for TLS domainComponent matching
Added TLS configuration for account resolver, TLS 1.3 logging, client‑IP exposure in INFO and subscription‑detail endpoints (routez/connz).
Add LogSizeLimit option for automatic log rotation
Add QueueSubscribe permissions and enhance Leafnode authentication (multi‑user, credentials, loop detection, daisy‑chaining).
Introduced new monitoring endpoints (/leafz) and RTT details in /routez, plus latency tracking for exported services and system‑level debugging tools.
Upgrade to Go 1.12.8 and adopt GoReleaser for building executables and Docker images; add Debian and RPM packages.
Bumped default TLS timeout to 2 seconds and added support to extend leafnode remote TLS timeout; re‑enabled insecure mode for remote leafnodes/gateways.
Introduced a new routing protocol with accounts, multi‑tenancy, NKey/JWT authentication, gateways, leaf nodes and TLS enhancements; not compatible with servers < 2.0.0 and requires import path change to /v2.
Updated build process to use Go 1.11.5 for binaries and Docker images.
Adds security measures: warns on plaintext passwords and redacts passwords in CONNECT traces.
Add Allow/Deny permissions, enabling subjects to be explicitly denied for users
- Added new monitoring capabilities: rtt metric, client‑ID filtering, closed‑connection reasons, sorting options, and expanded /subsz with subscription details and subject testing.
Added monitoring endpoints (Varz, etc.) and JSON configuration support.
Added ARM32v6 build, server ID to /connz and /routez, and client/cluster advertise address support
Added ARM64v8 release builds and a Systemd unit file
Fixed Windows Docker image startup failure caused by service controller connection error
Added numerous configuration options (connect retries, write deadline, curve preference, ChaCha cipher, auth token support, HTTP handler access, MonitorAddr/ClusterAddr, and runtime config reload).
Added new configuration features such as ping interval/max, integer suffixes, include files, max connections, log‑rotation via SIGUSR1 and automatic syslog tag generation.
Added option to hide cluster IP addresses and support IPv6 cluster URLs
Updated to Go 1.6.3 and rebuilt the Dockerfile accordingly.
- Updated to Go version 1.6.2
Added cluster auto‑discovery via seed hosts, Windows support, and upgraded to Go 1.6.2
Rebuilt the release with Go 1.4.2 to avoid issues present in Go 1.5