Redpanda Release Notes

This page lists the changes in each Redpanda release from version 26.2.2 onward, organized by version. For a curated summary of the major features in this release line, see What’s New.

v26.2.4 (2026-10-06)

Features

Cluster

The /v1/cluster_config/schema Admin API endpoint now includes each property’s default value, numeric bounds where applicable, and enterprise-license restrictions.

Cluster

sasl_mechanisms, log_cleanup_policy, transaction_coordinator_cleanup_policy, enable_consumer_group_metrics, and http_authentication now report their accepted values, and for sasl_mechanisms, which values require an enterprise license.

Bug fixes

Cloud Topics

The L0 write scheduler no longer corrupts the upload-group layout when concurrent upload-group splits and merges race, which previously degraded upload-throughput scaling.

Cloud Topics

L0 garbage collection on Azure Blob Storage now honors cloud_topics_short_term_gc_minimum_object_age. (No data is lost, because GC deletes only objects whose data is already in L1.)

Cloud Topics

The Cloud Topics metastore topic now reaches internal_topic_replication_factor as soon as enough brokers have joined a new cluster, instead of staying at a single replica for up to 10 minutes.

Cluster

A broker no longer aborts with an out-of-memory error after forwarding controller join and snapshot requests to itself following a controller-leader step-down.

Iceberg

Iceberg translation now supports backing the UUID logical type with the fixed(16) physical type in Avro schemas.

Kafka API

The internal Kafka client (used by Schema Registry, HTTP Proxy, and Shadow Link) no longer leaves a broker connection permanently unable to complete API-version negotiation, which previously caused repeated broker_not_available failures until the socket dropped for an unrelated reason.

Kafka API

The internal Kafka client no longer desyncs a connection’s protocol framing when a response arrives after its request has timed out; previously this caused cascading disconnects and stalled requests on that connection.

Schema Registry

Checking JSON Schema compatibility when a required property has a boolean subschema no longer aborts the broker.

Security

Broker-internal authorization probes (metadata visibility filtering, init_producer_id write fallback, the OffsetForLeaderEpoch fast path) no longer emit denied-access audit events attributed to the client. Previously a least-privilege client could generate O(topics) denied-access audit events that misrepresented broker-side checks as client-initiated access.

Security

OpenSSL is upgraded to 3.5.8, which addresses reported security vulnerabilities.

Security

Describing or deleting ACLs on clusters with many distinct ACL resource patterns no longer makes oversized memory allocations.

Security

OffsetForLeaderEpoch no longer logs a spurious authorization failure for non-superuser consumers.

Security

c-ares is upgraded to 1.34.8, which addresses CVE-2026-33630.

Storage

Records are no longer silently dropped from compacted topics after a partly successful log append.

Improvements

Cluster

Cross-shard partition movements now transfer the local log_eviction_stm snapshot, avoiding full local log replays.

Cluster

The health monitor no longer logs collecting cloud health statistics at INFO on every refresh when enable_usage is set; it now logs at DEBUG.

Schema Registry

A new redpanda_schema_registry_loaded_offset metric surfaces the last offset from the internal _schemas topic applied to the local store.

v26.2.3 (2026-09-17)

Bug fixes

Admin API

The usage-reporting Admin API endpoint no longer causes memory fragmentation.

Cloud Storage

The internal HTTP client no longer performs an out-of-bounds read when decoding a URI that ends with a truncated percent-escape.

Cloud Topics

The write-request scheduler no longer consumes a full CPU core on shards whose backlog cannot be uploaded.

Iceberg

Iceberg producer throttling now uses max_kafka_throttle_delay_ms as the throttle ceiling and quota_manager_gc_sec as the producer GC window. These two settings were previously flipped at the point of use.

rpk

rpk cloud login no longer fails with unable to find resource group for users who have only cluster-level permissions. rpk now falls back to the resource group ID when it cannot read the name.

rpk

The operations-stretch Grafana dashboard no longer mixes other operators' controllers into its reconcile, queue, and worker panels. Every panel now filters by new Namespace and Job pickers.

Schema Registry

JSON Schema compatibility checks now handle schemas that use fragment-only or fragment-bearing $id values. Previously these checks could resolve $ref values against the wrong subschema. Compatibility verdicts for affected schemas may change.

Schema Registry

JSON Schema compatibility checks no longer crash on schemas whose $ref targets a boolean or a non-schema value.

Schema Registry

Produce requests are now rejected if any schema-ID-validated key or value in a batch is invalid. Previously a batch could be accepted when only its last validated component was valid, which persisted invalid records.

Improvements

Cloud Storage

The internal HTTP client now fails a request with a timeout when the connection makes no I/O progress for 120 seconds. Previously the request stalled until TCP retransmission gave up, about 15 minutes, when a remote endpoint hung.

Cluster

Reconnection logic is hardened when inter-broker heartbeat requests hit a connection timeout.

Iceberg

Iceberg topics now persist statistics in Iceberg manifests. This allows more efficient pruning during queries.

Iceberg

Iceberg translation now honors several table properties that control how Parquet is written, including compression and Bloom filters.

Kafka API

The batch cache reclamation path is optimized to avoid reactor stalls on the fetch path.

rpk

The operations-stretch Grafana dashboard gains a Kubernetes cluster picker. It filters on the opt-in redpanda_k8s_cluster label set by the Redpanda operator chart’s monitoring.clusterLabel.

rpk

rpk -v now logs where each configuration value came from: the loaded config files, the selected profile and what selected it, and any values overridden by environment variables or -X flags. Secret values are never logged.

v26.2.2 (2026-08-21)

Features

rpk

rpk generate grafana-dashboard gains a new operations-stretch dashboard: a Grafana dashboard for stretch clusters managed by the Redpanda Operator, covering cross-cluster Raft health, StretchCluster member status, and operator reconcile health. Generate it with rpk generate grafana-dashboard --dashboard operations-stretch.

rpk

rpk generate grafana-dashboard now offers a load-factor dashboard showing utilization relative to capacity for key broker resources (CPU, I/O scheduler, disk IOPS, memory, network bandwidth, client connections).

Shadow Link

rpk now supports Shadow Link role sync in Redpanda Cloud clusters.

Shadow Link

rpk shadow update now accepts a --config-file flag to apply a configuration file directly.

Bug fixes

Cloud Topics

Timequeries on Cloud Topics no longer return an offset up to one indexing interval (4 MiB of records by default) later than the first record at or after the requested timestamp.

Cloud Topics

L0 batches in a Cloud Topic now preserve last_offset_delta in their header; previously an under-declared last offset could stall consumers, skip records, or halt exact-offset replication.

Cloud Topics

Timequeries on a Cloud Topic no longer fail by dropping the client connection or return an unfetchable offset below a partition’s start offset.

Cloud Topics

A Cloud Topic read replica on a cluster no longer prevents L0 objects on that cluster from being garbage collected.

Cloud Topics

Replication failures in Cloud Topics no longer trigger a rare crash.

Cluster

The leader_balancer_node_mute_timeout property now registers under the correct config name.

Cluster

Removing a partition with a very large number of log segments (for example, during partition rebalancing) no longer crashes the broker.

Cluster

Transient TOPIC_AUTHORIZATION_FAILED errors and SASL authentication failures no longer occur during application of a controller snapshot.

HTTP Proxy

Consumer group fetches no longer fail indefinitely with offset_out_of_range after retention moves a topic’s log start offset past 0; the consumer now recovers to the earliest available offset (auto.offset.reset=earliest).

Iceberg

Backpressure from the Iceberg coordinator no longer causes high CPU load on the translators.

Iceberg

The Iceberg coordinator’s snapshotting mechanism no longer stalls the reactor when a large number of Parquet files are pending commit.

Kafka API

The internal Kafka client no longer sends a concurrent request on a freshly established SASL connection before authentication finishes, which previously caused the broker to drop the connection.

Kafka API

The DescribeLogDirs request no longer crashes the broker.

Kafka API

Lifecycle fix on groups.

Kafka API

Redpanda no longer incorrectly accepts client-produced control batches.

Kafka API

The Kafka quota manager’s garbage collection no longer triggers a use-after-free during shutdown.

Redpanda Connect

rpk connect install --connect-version no longer rejects versions with a segment of three or more digits, which had blocked pinning any Redpanda Connect release since 4.100.0. Malformed versions with trailing characters are now rejected during validation rather than failing at download.

Redpanda Connect

rpk connect upgrade no longer fails to determine the currently installed Redpanda Connect version when that version has a segment of three or more digits, which had blocked upgrading any Connect install since 4.100.0.

rpk

rpk security secrets list no longer truncates its output at 100 secrets.

rpk

The rpk topic describe-storage command now produces valid output for tiered_v2 topics.

Schema Registry

With schema_registry_enable_authorization enabled, a Schema Registry request that fails before its deferred authorization check no longer aborts the broker; such requests now return an error response.

Shadow Link

Updating a Shadow Link that uses PLAIN authentication no longer fails when the password is omitted; the stored password is preserved.

Shadow Link

rpk shadow create no longer fails secret-reference validation on clusters with more than one page of REDPANDA_CLUSTER-scoped secrets.

Shadow Link

rpk shadow update in editor mode now replaces the entire Shadow Link configuration instead of merging changed fields, so list-valued fields (for example, topic filters) can shrink or be cleared.

Storage

A snapshot write that fails on a full disk (ENOSPC) now surfaces the I/O error instead of aborting the node with a misleading "snapshot writer has to be closed" assertion.

Storage

Topics with min.compaction.lag.ms left unconfigured are no longer considered ineligible for compaction when produced batches hold timestamps in the future.

Storage

Corrupted storage now yields a bad CRC in returned record batches.

Storage

Various s3_fifo users no longer grow unbounded under specific workloads.

Improvements

Admin API

The /v1/usage endpoint no longer causes oversized allocations for clusters with a large number of Iceberg-enabled topics.

Cloud Topics

Cloud Topics compaction now commits work in chunks, resulting in more stable compaction for partitions with a large amount of data.

HTTP Proxy

A consumer group now resumes from its committed offset on a fresh consumer instance instead of re-reading from the earliest available offset.

rpk

The default Redpanda Console image version in rpk container commands is now v3.9.0.

rpk

When producing or consuming with Schema Registry, rpk topic produce and rpk topic consume now read the topic’s redpanda.schema.registry.context with a DescribeConfigs request (unless --schema-context is given).

rpk

rpk topic alter-config now supports a --regex/-r flag to alter the config of all topics matching one or more regular expressions.

rpk

rpk topic produce and rpk topic consume now resolve Schema Registry schemas in the context bound to the topic via redpanda.schema.registry.context, and add a --schema-context flag to select the context explicitly.

rpk

rpk cluster health now displays any nodes that may be in maintenance mode.

Schema Registry

A new schema_registry_replay_on_startup cluster property (default off) hydrates the Schema Registry store at broker start-up rather than lazily on the first request.

Schema Registry

Some schema_registry and pandaproxy handler interfaces no longer make oversized allocations.

Schema Registry

The schema_registry recovery path now caches references when canonicalizing schemas.

Schema Registry

Schema Registry now logs whether a 403 on GET /schemas/ids/{id} was caused by a schema ID that does not exist or by missing ACLs. The response returned to clients is unchanged.

Schema Registry

Schema Registry now replays the internal _schemas topic exactly once when recovering on startup, instead of running redundant concurrent replays; cold start of a large registry is significantly faster.

Storage

The Cloud Topics and local storage compaction implementations now copy fewer records.

Storage

The key-value store now terminates the process on unrecoverable I/O errors in its flush path instead of silently stalling writes.

Release notes for older versions

Release notes for versions before 26.2.2 are published on GitHub. See the Redpanda releases page.