v2.14.2

envoyproxy/envoyv2.14.2Jun 2, 2026by github-actions[bot]

AI Summary

This release updates the Go runtime and dependencies, improving general functionality by exposing the client ID via API and fixing several race conditions and protocol-level corruptions.

Key Highlights

  • Client ID is now available through the embedded ClientAuthentication API
  • Fixed a race condition when handling subscription interest over routes
  • Fixed potential protocol-level corruption from rewriting $JS.ACK subjects
  • Fixed Raft peers tracking after inactivity stall during catchup

New Features

  • Client ID is now available through the embedded ClientAuthentication API

Full Release Notes

## Changelog

Refer to the [2.14 Upgrade Guide](https://docs.nats.io/release-notes/whats_new/whats_new_214) for backwards compatibility notes with 2.12.x. Please note that the 2.13.x version was skipped.

### Go Version

- 1.26.3

### Dependencies

- golang.org/x/crypto v0.52.0
- golang.org/x/sys v0.45.0
- github.com/nats-io/jwt/v2 v2.8.2
- github.com/nats-io/nkeys v0.4.16

### Improved

General

- The client ID is now available through the embedded `ClientAuthentication` API (#8217)

### Fixed

General

- A race condition when handling subscription interest over routes has been fixed (#8235)
- Potential protocol-level corruption from rewriting `$JS.ACK` subjects has been fixed (#8242)
- Potential protocol-level corruption from buffer misuse in compressed WebSocket clients has been fixed (#8244)
- The `/accstatz` monitoring endpoint no longer omits accounts with only leaf connections (#8252)

JetStream

- Fixed a case where Raft peers were not correctly tracked after an inactivity stall during catchup (#8226)
- Quorum needed is now calculated correctly when bootstrapping the metalayer when gateway URLs resolve to multiple IP addresses (#8238)
- The filestore no longer performs a block skip check on streams with extremely high subject counts, as it could result in runaway CPU usage (#8227)
- Fixed a case where the filestore would not release a lock after handling a write error (#8232)
- Purge operations on both file and memory stores are now more consistent with each other (#8241)
- Fixed a case where the consumer lock would not release a lock after handling a start sequence error (#8230)
- Counter streams and message schedules now have configuration constraints applied to prevent incorrect usage patterns (#8240)
- Improved stream and consumer scale down behaviour consistency (#8253)
- Fixed an issue where the per-subject state last block was not stored correctly with a max messages per subject limit of 1 (#8254)
- Fixed a drift that could occur in the peer sets after a peer remove of an online node (#8258)

### Complete Changes
 
https://github.com/nats-io/nats-server/compare/v2.14.1...v2.14.2