- Fixed numerous CVE‑related security issues, added a 1 MB JWT size limit, and ensured secrets and MQTT passwords are redacted in logs and endpoints.
- Resolved multiple panics and bugs across JetStream, leafnodes, MQTT, WebSockets, and duplicate header handling, improving overall stability.
- Enhanced JetStream commands (peer remove now accepts a peer ID), improved MQTT protocol compliance and error handling, and refined stream and leafnode behavior.