# Wowza Streaming Engine 4.11.2 released (security and bug fixes)

**URL:** https://community.wowza.com/t/wowza-streaming-engine-4-11-2-released-security-and-bug-fixes/102845
**Category:** Wowza Streaming Engine
**Created:** [July 23, 2026, 9:03am UTC](https://community.wowza.com/t/wowza-streaming-engine-4-11-2-released-security-and-bug-fixes/102845 "2026-07-23T09:03:18Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![Bernd\_Backhaus1](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/bernd_backhaus1/32/1328_2.png) [@Bernd\_Backhaus1](https://community.wowza.com/u/Bernd_Backhaus1)
#### Post date: [July 23, 2026, 9:03am UTC](https://community.wowza.com/t/wowza-streaming-engine-4-11-2-released-security-and-bug-fixes/102845/1 "2026-07-23T09:03:18Z")

</div>

Hello everybody,

Wowza Streaming Engine version 4.11.2 has been released, providing security and bug fixes.

Please see the

[complete 4.11.2 release notes](https://www.wowza.com/docs/wowza-streaming-engine-4-11-2-release-notes)

for a detailed list of changes, update and improvements, which is repeated below:

**Version:** Wowza Streaming Engine™ 4.11.2+6 build 20260722195619 released June 22, 2026.

**Java support:** Wowza Streaming Engine 4.11.0 is compiled using Java 17 (OpenJDK Java SE JRE 17.0.12) but can be used with Java versions 17 or 21. For more details, see [Java version information](https://www.wowza.com/docs/wowza-streaming-engine-4-9-7-release-notes#java-version-information).

## New features and functionality

* * *

This release focuses on stability and security. Three third-party libraries were updated to patch known CVEs: SRT (1.5.6), Spring Boot (3.5.14), and Jackson Core (2.18.9). On the bug fix side, a freeze affecting concurrent HLS liverepeater edge streams (introduced in 4.11.0) has been resolved — customers running HLS liverepeater edges should upgrade. Additional fixes address a `ConcurrentModificationException` during live ingest, reduce CPU overhead during live stream buffer flushes, and add missing HSTS headers to 404 responses.

## Detailed list of changes

* * *

### Security

- Updated the SRT library to version 1.5.6 to resolve[CVE-2026-55869](https://www.cve.org/CVERecord?id=CVE-2026-55869) and [CVE-2026-55868](https://www.cve.org/CVERecord?id=CVE-2026-55869).
- Updated Spring Boot to version 3.5.14 to resolve [CVE-2026-40973](https://www.cve.org/CVERecord?id=CVE-2026-40973).
- Updated Jackson Core to version 2.18.9 to resolve [CVE-2026-54512](https://www.cve.org/CVERecord?id=CVE-2026-54512), [CVE-2026-54513](https://www.cve.org/CVERecord?id=CVE-2026-54513).

### Bug Fixes

- A bug introduced in 4.11.0 causing apps processing concurrent HLS liverepeater edge streams to freeze and require a restart has been fixed.
- Customers using HLS liverepeater edges should upgrade their version.
- Reduced CPU overhead in live stream buffer flushes by trimming stale packets before copying the buffer.
- Fixed a bug in live streams causing `ConcurrentModificationException` errors and log noise.
- HSTS headers were previously missing in 404 responses and have been added.

## Known issues

* * *

For a detailed list of currently known issues, see [Known issues with Wowza Streaming Engine](https://www.wowza.com/docs/known-issues-with-wowza-streaming-engine "Known issues with Wowza Streaming Engine").

Regards,  
**Bernd Backhaus**  
Technical Support Engineer  
**WOWZA** | _The **solution** you start with, the **partner** you scale with._

**[Manage your Support cases online](https://portal.wowza.com/account/support)**  
**Bookmark our** **[FAQ page](https://support.wowza.com/hc/en-us)**  
**Bookmark our** **[Status page](https://status.wowza.com/)**

![182x66.9749984741211](https://api-na1.hubspot.com/filemanager/api/v2/files/189182705952/signed-url-redirect?portalId=229276)
