# Wowza Streaming Engine 4.11.0 Released: Features, Security Patches & Transcoder Updates

**URL:** <https://community.wowza.com/t/wowza-streaming-engine-4-11-0-released-features-security-patches-transcoder-updates/102834>\
**Category:** Wowza Streaming Engine\
**Created:** [June 18, 2026, 9:47am UTC](https://community.wowza.com/t/wowza-streaming-engine-4-11-0-released-features-security-patches-transcoder-updates/102834 "2026-06-18T09:47:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bernd\_Backhaus1](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/bernd_backhaus1/32/1328_2.png) [@Bernd\_Backhaus1](https://community.wowza.com/u/Bernd_Backhaus1)\
**Post date:** [June 18, 2026, 9:47am UTC](https://community.wowza.com/t/wowza-streaming-engine-4-11-0-released-features-security-patches-transcoder-updates/102834/1 "2026-06-18T09:47:17Z")

</div>

Hello everybody,

Wowza Streaming Engine version 4.11.0 has been released, with major updates to WebRTC functionality

Please see the

[complete 4.11 release notes](https://www.wowza.com/docs/wowza-streaming-engine-4-11-0-release-notes)

for a detailed list of changes, update and improvements, which s repeated below:

This release introduces a modernized WebRTC stack with broader standards support, more reliable connectivity, and a number of fixes.The existing WebRTC implementation continues to work unchanged.

### New capabilities

- WHIP and WHEP support — publish to and play from Wowza Streaming Engine using the standard WHIP (ingest) and WHEP (egress) protocols, enabling interoperability with third-party tools such as OBS, FFmpeg, and GStreamer.
- Configurable STUN and TURN servers — set STUN and TURN servers (with TURN authentication) per application from Wowza Streaming Engine Manager or in `Application.xml` to improve connection success across NATs and restrictive firewalls.
- Improved connectivity (ICE) — full ICE candidate gathering and connectivity checks, trickle ICE for faster connection setup, and TCP ICE candidate support for networks where UDP is blocked.
- Expanded codec support — added HEVC (H.265) and VP9 for WebRTC, with automatic codec negotiation.
- Multiple IP / NIC support — WebRTC now works on secondary public IP addresses and additional host ports, not just the primary network interface.
- Edge/Origin playback — WebRTC playback is supported from Edge applications repeating streams from Origin applications.
- Secure token protection — WebRTC streams can be protected using secure tokens.
- Connection monitoring — the Application Monitoring page now displays the current WebRTC connection count.
- Updated example pages — the WebRTC publish and playback example pages were modernized, including WHIP/WHEP selection, STUN/TURN configuration fields, and trickle ICE support.

### Resolved WebRTC issues

- Fixed WebRTC publishing failures from Firefox.
- Fixed WebRTC connection failures on servers using ECC (Elliptic Curve) SSL certificates.
- Fixed Safari (iOS and macOS) playback failures for transcoded WebRTC streams delivered over HLS/LL-HLS.
- Fixed missing video on certain 720p streams published over WebRTC.
- Fixed WebRTC failures when using a server’s secondary public IP address.
- Fixed video artifacts and interruptions when transcoding RTMP sources to WebRTC.
- Fixed missing audio when publishing WebRTC from certain mobile devices.
- Fixed severe frame-rate drops when publishing higher-resolution WebRTC from Firefox.

## Improvements

- Added built-in PDT support for HLS streams. Users can now configure PDT tags directly in the `Application.xml` file and no longer need to install the `ModuleCupertinoProgramDateTime` module. The PDT tags can be configured with the following properties:
  - `cupertinoEnableProgramDateTime`: Emit a PDT on the first chunk and at discontinuities
  - `cupertinoEnableProgramDateTimePerSegment`: Emit a PDT on every segment
  - **Note** : This implementation is backward compatible—custom timestamps assigned via the `ModuleCupertinoProgramDateTime` module or the `chunk.setProgramDateTime(...)` function will override the auto-populated wall-clock.

- Fixed a bug related to the HLS `cupertinoClosedCaptionValue` property that prevented the subtitle button on iOS players from being disabled.
- UX Improvement: A GPUID field has been added to the Decode section in WSE Manager. Users can now configure GPU transcoding workflows without editing XML.
- The default TCP send and receive buffer values for newly created vhosts and newly created host ports have been updated.
- Suppressed verbose Log4j configuration startup messages in the update tool by changing the status log level from INFO to WARN.
- Improved Transcoder stability under mixed CPU/GPU workloads.
- Optimized GPU Transcoder performance for workflows that involve Overlays and Watermarks.
- WebRTC improvements:
  - Added support for WHIP/WHEP WebRTC streams, including support for bearer tokens. Once a bearer token is configured for an application, WSE will validate the Authorization header of incoming WHIP/WHEP requests against it. To require a bearer token on WHIP/WHEP streams you may:
    - Generate a bearer token using WSE Manager
    - Generate your own bearer token and add it to the application’s configuration file (`Application.xml`).
    - **(Note:** For independent access control, WHIP and WHEP must use separate tokens.)

  - A new element was added to `VHost.xml`. The new `<SelectedVersion>` element is nested within the existing `<WebRTC>` element. It allows apps to select WSE’s default WebRTC implementation. The `<SelectedVersion>` is set to `v2` by default. To support legacy RTC streams, you may change `<SelectedVersion>` to either of the following values:
    - `legacy`: All WebRTC streams will use the legacy (`v1`) WebRTC implementation.
    - `dynamic`: Support both `v1` and `v2` WebRTC implementations.  
Include `?webrtcImplementation=v2` in HTTP requests to use `v2`; otherwise defaults to `v1`.
    - Note: In previous versions of WSE, `VHost.xml` does not contain a `<SelectedVersion>` element.  
In this case, WSE will automatically default to `dynamic` mode, ensuring backward compatibility without requiring configuration changes.

## Bug Fixes

- Fixed out-of-memory errors in push-publish workflows when CDN becomes unreachable. Time-based cleanup purges segments after timeout, with discontinuity tags maintaining stream integrity.
- Fixed a bug causing memory exhaustion and CPU spikes when MediaCaster sources are unavailable. DNS lookups are now cached to reduce connection overhead. Connection timeouts and per-source bind address settings are now properly honored.
- Fixed memory leaks in HTTP playback sessions caused by incomplete session cleanup. Idle worker errors are now caught and logged, ensuring proper session cleanup when playback ends.
- Fixed a memory leak in `RTPDePacketizerWrapperPacketSorter` affecting streams with intentional packet duplication. In high-latency streams configured with jitter buffer, duplicate RTP packets caused unbounded heap growth, resulting in server crashes.
- Fixed a bug in MainConcept CPU transcoding, in which the transcoded video was slightly darker than the source video.
- Fixed an issue decoding RTSP published H.265/HEVC video streams.
- Fixed a bug causing video quality degradation when using a combination of: CUDA scaling, NVCUVID decoding, and NVENC GPU encoding.
- Fixed a parameter alignment issue in MainConcept transcoder initialization causing incorrect encoding parameters (affecting H.265 encoding, in particular).
- Fixed an issue where transcoder sessions were not being properly removed from the session map. In some cases, duplicate entries caused accounts to reach their transcode session limit prematurely.
- Fixed LL-HLS CMAF playlist generation to correctly report rendition information, resolving Apple `mediastreamvalidator` validation errors.
- The application-specific directory `content/[AppName]/` is now created during new application setup. Previously, this directory was not created, resulting in a ‘Streaming File Directory does not exist’ error.
- Fixed a bug introduced in WSE v4.9.7 that produced a false “Untracked publisher stream” warning for each transcoder output stream. These false alarms have been eliminated.

Regards,  
**Bernd Backhaus**  
Technical Support Engineer  
**WOWZA** | _The **solution** you start with, the **partner** you scale with._

**[Manage your Support cases online](https://portal.wowza.com/account/support)**  
**Bookmark our** **[FAQ page](https://support.wowza.com/hc/en-us)**  
**Bookmark our** **[Status page](https://status.wowza.com/)**

![182x66.9749984741211](https://api-na1.hubspot.com/filemanager/api/v2/files/189182705952/signed-url-redirect?portalId=229276)

---

<div class="post-metadata">

**Author:** ![vigneshini.i](https://avatars.discourse-cdn.com/v4/letter/v/8c91f0/32.png) [@vigneshini.i](https://community.wowza.com/u/vigneshini.i)\
**Post date:** [July 12, 2026, 6:16pm UTC](https://community.wowza.com/t/wowza-streaming-engine-4-11-0-released-features-security-patches-transcoder-updates/102834/2 "2026-07-12T18:16:21Z")

</div>

**Amazon IVS remains Offline although Wowza Stream Target is Active (Wowza 4.11.0+24)**

### **Environment**

- Wowza Streaming Engine 4.11.0+24
- Java 21
- Single transcoded output (480p)
- Push Publish to Amazon IVS via RTMPS

### **Issue**

After upgrading from **Wowza 4.8.x** to **4.11.0+24** , we intermittently observe the following issue:

- Source stream is successfully published to Wowza.
- Recording and local HLS playback work correctly.
- Push Publish Stream Target remains **Active**.
- Amazon IVS reports the channel as **Offline** and receives no media.
- Restarting the Wowza server immediately restores publishing to IVS.

### **Relevant Logs**

```auto

```

```auto
TranscoderSessionVideo.addPacket[...] Video packet list is full: size:7200 limit:7200
TranscodingSession.updateBehindFilter... SKIP2FRAME
TranscodingSession.updateBehindFilter... SKIP4FRAME
TranscodingSession.updateBehindFilter... KEYFRAMESONLY

```

### **Resource Usage**

- CPU: 1–2% overall (Wowza Java process: 6–13%)
- Memory: ~2.5 GB / 62 GB

This does not appear to be a resource issue.

### **Questions**

- Is this a known issue in Wowza 4.11.0+24?

---

<div class="post-metadata">

**Author:** ![Bernd\_Backhaus1](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/bernd_backhaus1/32/1328_2.png) [@Bernd\_Backhaus1](https://community.wowza.com/u/Bernd_Backhaus1)\
**Post date:** [July 13, 2026, 3:23pm UTC](https://community.wowza.com/t/wowza-streaming-engine-4-11-0-released-features-security-patches-transcoder-updates/102834/3 "2026-07-13T15:23:06Z")

</div>

Hello,

Thank you for reaching out.

We did not get any reports related to this behavior.

Would you mind opening a [Support Ticket](https://support.wowza.com/techsupport-request) and include [conf and logs](https://www.wowza.com/docs/how-to-create-a-compressed-zip-file-for-support-tickets), ideally collected right after the issue happened.

Any further details on the workflow might be helpful as well.

Thank you!

Regards,  
**Bernd Backhaus**  
Technical Support Engineer  
**WOWZA** | _The **solution** you start with, the **partner** you scale with._

**[Manage your Support cases online](https://portal.wowza.com/account/support)**  
**Bookmark our** **[FAQ page](https://support.wowza.com/hc/en-us)**  
**Bookmark our** **[Status page](https://status.wowza.com/)**

![182x66.9749984741211](https://api-na1.hubspot.com/filemanager/api/v2/files/189182705952/signed-url-redirect?portalId=229276)
