- Patched critical CVE‑2025‑30215 affecting all NATS Server versions prior to v2.11.1/v2.10.27.
- Added proper account validation for several system API calls and enforced system/account limits during stream restore.
- Fixed a performance regression when max messages per subject is 1 and corrected JetStream validation issues.