NEAR published nearcore 2.13.4 as a security-focused release. Its official notes explicitly set `SECURITY_UPGRADE: TRUE`, while both `PROTOCOL_UPGRADE` and `DATABASE_UPGRADE` remain `FALSE`. The project says the release fixes critical flaws in nearcore that could cause a node crash or denial of service.
Operationally, this means node operators do not need to wait for a protocol activation to obtain the fix: the change is in node software rather than a new protocol version or mandatory database migration. The release notes advise upgrading as soon as possible to avoid downtime.
Validators and full-node operators should still monitor startup, peer connectivity, block processing and resource behavior after deployment, as with any security patch. The absence of a database upgrade reduces migration complexity but does not remove the need for normal rollback planning and compatibility checks with local deployment tooling.
For NEAR, the release is an infrastructure-security event rather than a change to token economics. Its direct effect is reducing exposure to node-level crash and DoS flaws for operators that deploy the patched build.
