Omni Gateway running in Connected Mode no longer disconnects unexpectedly from Anypoint Platform under high-traffic conditions or when the remote server sends data without replying with protocol-level pong frames.
|
|
Custom policies no longer crash Omni Gateway with a segmentation fault when a response payload is larger than the buffer limit (1 MB by default). Use the FLEX_DOWNSTREAM_CONNECTION_BUFFER_LIMIT_BYTES environment variable to increase the buffer limit.
|
|
The Basic Authentication: LDAP policy no longer lets specially crafted usernames to manipulate the underlying LDAP search filter.
|
|
Resetting Redis shared storage no longer fails with a cross-slot error in cluster-mode deployments (such as AWS ElastiCache).
|
|
Control node no longer discards synchronization state after 14 days to prevent inconsistencies when a gateway reconnects following an extended outage.
|
|
Control node Redis shared storage no longer grows without bound over time from historical configuration-change data.
|
|
Omni Gateway running in Connected Mode no longer disrupts running pods when its registration credentials are renewed.
|
|
Control node no longer delays propagating a configuration update or logs a false inconsistency warning after a transient failure while committing that update.
|
|
Control node no longer fails to apply deployment updates when multiple replicas write to the same resource at nearly the same time.
|
|
Custom policies no longer cause a memory leak that can increase memory usage over time.
|
|
Omni Gateway no longer produces a malformed path predicate (such as a duplicate or missing slash) when a negative-lookahead path pattern is combined with an API base path.
|
|
Omni Gateway running in Connected Mode no longer sends duplicate deployment-status updates to Anypoint Platform.
|
|
The JWT Validation policy no longer bypasses the configured forward proxy when fetching JWKS keys.
|
|
The Credential Injection OAuth 2.0 policy no longer ignores the configured caching duration when the OAuth 2.0 provider’s token response omits the token expiration value.
|
|
The Rate Limiting SLA policy with distributed rate limiting enabled no longer crashes the gateway (WASM trap, returning a 503 error instead of 429) under Redis latency and high concurrency on the same SLA tier.
|
|
The OpenID Connect OAuth 2.0 Token Enforcement and OAuth 2.0 Token Introspection policies no longer forward the raw error response from the introspection server to the client.
|
|
The OpenID Connect OAuth 2.0 Token Enforcement and OAuth 2.0 Token Introspection policies no longer return a 503 error on all requests when the exposeHeaders option is enabled and a token claim’s name contains characters that aren’t valid in an HTTP header name.
|
|
The OAuth 2.0 Token Introspection policy no longer fails when the introspection URL includes an explicit default port.
|
|
These vulnerabilities detected by scanners are now fixed:
-
CVE-2022-27943
-
CVE-2025-27587
-
CVE-2026-41178
-
CVE-2026-42767
|
-
CVE-2026-56852
-
CVE-2026-73500
-
GHSA-259r-337f-4rfw
-
GHSA-hrxh-6v49-42gf
|
|
W-23490974, W-23559915, W-23735964, W-23862957
|