Contact Us 1-800-596-4880

Mule Runtime Engine 4.13.0 Release Notes

Mule runtime engine (Mule) is a lightweight integration engine that runs Mule applications and supports domains and policies.

This version of Mule provides important enhancements and fixes. Deploy all your new and existing applications to the latest version to benefit from the improvements.

For guidance with the patching process, see Apply Patch Updates.

October 6, 2026

What’s New

The 4.13.0 version of Mule runtime introduces these enhancements:

Cache Scope:

  • Mule 4.13 updates the Cache scope so that it persists only the message payload and attributes instead of the full Mule event. The mule.serialize.message.in.cache feature flag controls this behavior, and Mule migrates existing cache entries from the full-event format on demand. As a result, the Key Generator, Response Generator, and Event Copy Strategy customizations are deprecated for applications that set minMuleVersion to 4.13.0 or later. See Set Up a Caching Strategy for a detailed description of the feature.

OpenTelemetry Direct Telemetry Stream:

See OpenTelemetry Support in Mule Runtime for a detailed description of the feature.

  • Tracing:

    • You can now set the OpenTelemetry tracing level for specific components or flow locations, in addition to the application-wide level. See Tracing Levels for more information.

    • Traces for the same API resource now share one span name. When APIkit Router routes a request, the root span name uses the HTTP method and the matched route template, such as GET /api/books/{bookId}, instead of the raw listener path.

    • The Mule Tracing module now includes the add-root-span-attributes operation, which adds custom attributes to a transaction’s root span from anywhere in the flow. See Add Root Span Attributes for more information.

  • Metrics:

    • Flow statistics counters (received.events, dispatched.messages, execution.errors, fatal.errors, and dispatched.primary.messages) now report per-flow values by default through the mule.flow.name attribute. See Message Processing Metrics for more information.

    • You can now set service.name and service.namespace for JVM metrics at the container level, separately from the application level. See Custom Service Name and Service Namespace for more information.

    • You can now set the aggregation temporality for exported metrics through the mule.openTelemetry.meter.exporter.aggregationTemporality property. Supported values are CUMULATIVE (default), DELTA_PREFERRED, LOW_MEMORY, and FULLY_DELTA. See Metrics Temporality for more information.

  • Resource Attributes:

    • Mule runtime now adds a mule.artifact.type resource attribute (app, domain, or policy) to every exported span, log record, and metric data point. See Automatically Added Resource Attributes for more information.

    • Anypoint Platform metadata resource attributes now use the mule.anypoint. prefix, for example, mule.anypoint.org.id. All Mule-generated attribute keys in traces, logs, and metrics now use dot notation. The previous unprefixed keys are deprecated, but Mule still exports them alongside the new keys. See Automatically Added Resource Attributes for more information.

Feature Flagging Mechanism:

  • Mule 4.13 incorporates new feature flags. See Feature Flagging Mechanism for a detailed description of each feature flag and configuration instructions.

Runtime Manager agent:

DataWeave Features

The 2.13.0 version of DataWeave introduces these new features and enhancements:

JSON Web Token Signing:

  • DataWeave introduces the dw::util::jwt::HMAC module for creating signed JSON Web Tokens (JWTs) with the HS256, HS384, and HS512 algorithms. See HMAC (dw::util::jwt::HMAC).

  • DataWeave introduces the dw::util::jwt::RSA module for creating signed JWTs with the RS256, RS384, and RS512 algorithms using unencrypted PKCS#1 or PKCS#8 PEM private keys. See RSA (dw::util::jwt::RSA).

Fixed Issues

The release addresses these Mule issues and incorporates all patch updates from the 4.12.0 Mule release through October 2026:

Issue Resolution ID

The jsoup library is upgraded to 1.23.2.

W-23987955

The Jackson library is upgraded to 2.22.3.

W-24335732

The Reactor Core library is upgraded to 3.8.7.

W-23987958

The Netty library is upgraded to 4.2.18.Final.

W-24336011

The Apache Neethi library is upgraded to 3.2.4.

W-24335736

The Spring Framework library is upgraded to 7.0.9.

W-24232049

The raml-parser-2 library is upgraded to 1.2.1.

W-23570110

Error-mapping preservation during error propagation is now enabled by default. An error whose type was already resolved inside a scope, including any remapping by an error mapping, now keeps that resolved type as it propagates out of the scope, instead of reverting to the raw connector error type. You can disable this behavior by setting the mule.honourErrorMappingsOnErrorPropagation system property to false.

W-23955755

OpenTelemetry metric exporters now support per-exporter view enrichment and resource attribute overrides.

W-23367495

JSON schema validation is migrated from the everit library to networknt, with everit retained as a fallback.

W-16530105

HTTP header values containing CR/LF characters are now sanitized instead of causing the request to be rejected.

W-22252135

minMuleVersion values are now normalized when loaded, preventing the patch or revision portion from being truncated.

W-24231362

Configuration property placeholder resolution now stops once it exceeds a maximum nesting depth, instead of continuing to recurse through a cyclic or excessively deep reference chain. You can configure the depth limit through the mule.properties.resolution.maxDepth system property, which defaults to 10.

W-23650198

Reads from the repeatable streaming buffer are now lock-free when data is already available, reducing thread contention. You can control this behavior by using the mule.repeatableStreaming.lockFreeRead system property.

W-24012839

You can now configure a full request timeout for the HTTP server by using the mule.http.server.fullRequestTimeout system property, in milliseconds. This property is disabled by default.

W-22040113

OpenTelemetry flow-statistics counters now emit one datapoint per flow, labeled with the mule.flow.name dimension, instead of a single artifact-level total. You can disable this behavior by setting the mule.enable.otel.flow.statistics.detailed system property to false.

W-23616483

Logging export reconfiguration is fixed for single application mode.

W-20908857

The ObjectStore API is extended with an upsert operation and an isThreadSafe indicator.

W-23090592

An omitted eagerRead attribute on <repeatable-in-memory-stream> now correctly takes its default value from the mule.repeatableStreaming.bytes.eagerRead system property, instead of a fixed value.

W-24043809

A java.lang.UnsupportedClassVersionError thrown when a connector’s compiled target doesn’t match the running JVM is now handled gracefully.

W-24193358

A connector’s message source no longer deadlocks when its connection-retry logic triggers a stop of the retry scheduler from one of that scheduler’s own worker threads.

W-24234538

Network information listening ports are now scoped to the Mule process.

W-24043880

NullPointerException errors no longer occur when loading the extension model of a connector whose connection provider uses the @ClientCredentials or @AuthorizationCode OAuth annotation with credentialsPlacement configured.

W-24086656

Policy logging context is no longer lost when a dynamic Flow Reference resolves to a subflow.

W-24026465

The new loggingConfiguration troubleshooting operation helps you diagnose logging configuration issues.

W-23998256

The log level for disallowConcurrentExecution messages is changed from WARN to DEBUG, reducing log noise.

W-24164028

The new on-demand connectivity-testing troubleshooting operation is now available.

W-23629284

The OpenTelemetry exporter TLS property mule.openTelemetry.exporter.tls.certificatesStrategy is now properly resolved.

W-24009827

A source policy that uses Async, Parallel For Each, or Scatter-Gather no longer builds its response from the failure response parameters instead of the success response parameters, and no longer silently drops the forked route’s response processing.

W-23938349

The new on-demand connectionCount troubleshooting operation is now available.

W-23716301

The commons-beanutils library and its transitive commons-collections 3.2.2 dependency are removed from Mule Runtime modules.

W-16918287

OpenTelemetry metrics export now supports delta aggregation temporality.

W-23448781

An unresolved placeholder in the meter-exporter configuration now degrades to its default value at tracer startup instead of causing a failure.

W-23650358

Dynamic reload of the metrics exporter configuration is now supported.

W-21921629

OpenTelemetry flow statistics counters now report total flow counts as well as per-flow totals.

W-23232729

OutputHandler is deprecated and its support is removed.

W-23660888

A SerializationException now raises a MULE:SERIALIZATION error, instead of MULE:UNKNOWN.

W-21381359

The exporter-health backpressure-alert cadence for OpenTelemetry tracing, metrics, and logging is now configured through a single system property, mule.openTelemetry.meter.exporter.healthMetrics.alertingFrequency, instead of the separate per-signal metricsLogFrequency properties, which are deprecated and no longer consumed.

W-22193713

MULE:INVALID_INPUT_PARAM is now preserved as a suppressed error when a MULE:SOURCE_RESPONSE_GENERATE error occurs.

W-22293407

SDK parameter validation errors are now mapped to the MULE:INVALID_INPUT_PARAM error type.

W-2227652

Mule-generated tracing spans no longer truncate attribute values at OpenTelemetry’s default 128-character limit. Attribute values are now preserved up to 4096 characters before truncation.

W-20091299

Client-side read backpressure is now applied to streamed HTTP responses, preventing out-of-memory errors when consuming large response bodies.

W-24103497

The Netty-based HTTP client now defers DNS resolution of the target host to the proxy when a proxy is configured, regardless of the configured scheme.

W-24010245

Unresolved placeholders in Batch AST properties no longer cause a ClassCastException during packaging validation.

W-24088827

In a clustered deployment, the DiscoverySPI HTTP client no longer fails to start when PCF or Kubernetes discovery is configured through the .mule/mule-cluster.properties file instead of a JVM system property.

W-24211100

SQSQueueManagementService is added to the serialization allowlist.

W-24197744

Fallback is now enabled as the default strategy for contracts collection. You can change this behavior by configuring the anypoint.platform.clients_fetch_mode system property with the values sharded, legacy, or fallback.

W-24179706

When API Gateway authenticates with Anypoint Platform, a transient failure of the /login request no longer discards an otherwise valid Access Management token. The token is now invalidated only on an actual authentication failure (401 or 403).

W-24144244

Netty’s Java Flight Recorder (JFR) integration is now disabled by default.

W-20926401

DataWeave 2.13.0 is bundled with the Mule 4.13.0 release. This release addresses these DataWeave issues:

Issue Resolution ID

Memory usage for text/plain output is reduced.

W-20063270

Eagerly materialize executable Weave reader results.

W-23837275

Thread safety is improved when processing Java map values.

W-23661641

DataWeave tooling now reports design-time warnings when Java classes referenced in application/java schemas can’t be found or are inaccessible through JPMS.

W-22797049

DataWeave now filters Java classes in JPMS-unexported packages during Java module resolution, preventing runtime IllegalAccessException failures. This behavior is enabled by default on JDK 17 and later with DataWeave language version 2.13 and later. To keep the previous behavior, set mule.dw.filter_jpms_inaccessible_modules=false.

W-22779527

Cryptographic security warnings and errors now include call stacks.

W-22144340

Bundled Components

  • DataWeave version 2.13.0

  • Runtime Manager Agent plugin version 2.8.5

Upgrade

If you’re upgrading to this version of Mule from an earlier Mule 4.x version, see Mule Upgrades and Patch Updates.

To ensure optimal performance with this version of Mule and avoid unexpected issues, update these modules and extensions to their latest version at the time of this release:

Module or Extension Version

APIkit for Mule 4

1.11.17

APIkit for OData

2.4.0

APIkit for OData 4

1.6.0

APIkit for SOAP

2.1.0

APIkit for GraphQL

1.2.0

Spring module

2.1.2

MUnit plugin

3.7.1

Considerations for Mule Extension Developers

When you build a Mule extension, if you update the version of your parent pom.xml file to 1.4.0 or later, ensure that the dependencies in your pom.xml file don’t override dependencies in the parent pom.xml file. Declare only the dependencies you need. If you declare a dependency that’s already in the parent pom.xml file, don’t specify a version, so that it uses the version from the parent pom.xml file.