Redpanda Release Notes
This page lists the changes in each Redpanda release from version 26.1.18 onward, organized by version. For a curated summary of the major features in this release line, see What’s New.
v26.1.18 (2026-09-24)
Bug fixes
- Cloud Storage
-
The internal HTTP client no longer performs an out-of-bounds read when decoding a URI that ends with a truncated percent-escape.
- Cloud Topics
-
The write-request scheduler no longer consumes a full CPU core on shards whose backlog cannot be uploaded.
- Iceberg
-
Iceberg producer throttling now uses
max_kafka_throttle_delay_msas the throttle ceiling andquota_manager_gc_secas the producer GC window. These two settings were previously flipped at the point of use. - Kafka API
-
A broker connection in the internal Kafka client (used by Schema Registry, HTTP Proxy, and Shadow Link) no longer gets stuck unable to complete API version negotiation. Previously such a connection could fail repeatedly with
broker_not_availableuntil the socket dropped for an unrelated reason. - Kafka API
-
A response that arrives after its request has already timed out no longer desyncs the internal Kafka client connection’s protocol framing. Previously this could cause cascading disconnects and stalled requests on that connection.
- Kafka API
-
The Kafka quota manager no longer triggers a use-after-free during shutdown in its garbage collection.
- Schema Registry
-
JSON Schema compatibility checks now handle schemas that use fragment-only or fragment-bearing
$idvalues. Previously these checks could resolve$refvalues against the wrong subschema. Compatibility verdicts for affected schemas may change. - Schema Registry
-
JSON Schema compatibility checks no longer crash on schemas whose
$reftargets a boolean or a non-schema value. - Schema Registry
-
A JSON Schema compatibility check no longer aborts the broker when a required property has a boolean subschema.
- Schema Registry
-
Produce requests are now rejected if any schema-ID-validated key or value in a batch is invalid. Previously a batch could be accepted when only its last validated component was valid, which persisted invalid records.
- Security
-
Describing or deleting ACLs on clusters with many distinct ACL resource patterns no longer causes oversized memory allocations.
- Security
-
OpenSSL is upgraded to 3.5.8, which addresses reported security vulnerabilities.
- Security
-
c-ares is upgraded to 1.34.8, which addresses CVE-2026-33630.
- Storage
-
Records are no longer silently dropped from compacted topics after a partly successful log append.
- Tiered Storage
-
Metadata spillover no longer gets permanently stuck on partitions with small, frequent segments. Previously it could repeatedly log
Can’t apply spillover_cmdand leave orphaned spillover manifest objects in the bucket.
Improvements
- Cloud Storage
-
The internal HTTP client now fails a request with a timeout when the connection makes no I/O progress for 120 seconds. Previously the request stalled until TCP retransmission gave up, about 15 minutes, when a remote endpoint hung.
- Cluster
-
Reconnection logic is hardened when inter-broker heartbeat requests hit a connection timeout.
- Cluster
-
Cross-shard partition movements now transfer the local
log_eviction_stmsnapshot. Previously the missing snapshot led to full local log replays. - Schema Registry
-
A new
redpanda_schema_registry_loaded_offsetmetric surfaces the last offset from the Schema Registry’s internal_schemastopic applied to the local store.
Release notes for older versions
Release notes for versions before 26.1.18 are published on GitHub. See the Redpanda releases page.