Serguey Asael Shinder: Kotlin 2.4.21 fixes JSR-223 eval breaking after Java bindings and a reflection crash
JetBrains published Kotlin 2.4.21 on 8 October, a bug-fix release on the 2.4 line with twelve tracked issues. Most of them sit in places a Java team meets when Kotlin is embedded rather than used as the main language: scripting through JSR-223 (javax.script), kotlin-reflect looking at Java classes, and Kotlin scripts with dependencies.
Scripting through javax.script.
- KT-89220: in the JSR-223 engine, a binding with a generic Java type broke every subsequent
eval()call on that engine, not only the one that used it. For applications that expose Java objects to user scripts through engine bindings and keep the engine alive, that is the difference between one failing script and a dead scripting feature until restart. - KT-89247: running a Kotlin script a second time failed with
NoClassDefFoundErrorwhen it had a transitive dependency from an imported script. The first run worked, which is the pattern that slips through tests. - KT-88453 and KT-88458:
VirtualFileScriptSource.textleft a file stream unclosed, so the script's source file stayed open until garbage collection and could not be deleted on Windows; the release also includes an audit of closeable-resource use in the scripting code.

Reflection on Java classes. KT-89280 fixes a NoSuchElementException thrown inside kotlin-reflect for a non-static inner class of a generic outer class written in Java — for example Outer<T>.Inner. Frameworks that use Kotlin reflection on mixed Java and Kotlin models (serialisation, dependency injection, mapping libraries) are the likely place to meet it. A related change, KT-80710, changes how KCallable is represented so that reflection no longer depends on the old K1 compiler.
Other targets. For Kotlin/JS, KT-89449 restores minification of member names in production builds — they had stopped being minified — and KT-89363 lets a regular class with a companion object extend an external class. For Kotlin/Wasm, a lambda typed (T) -> R called with a non-T argument now throws ClassCastException instead of trapping (KT-89267), and @Serializable generic classes with a class upper bound no longer produce invalid Wasm (KT-89275). On Kotlin/Native, SwiftPM import no longer floods the log (KT-89285), and a flaky Linux link failure is addressed (KT-86251).
Who should update. Anyone embedding Kotlin scripting in a JVM application — especially through javax.script with Java bindings — and anyone shipping Kotlin/JS to production, where member names were no longer minified. For a plain Kotlin JVM service that uses neither scripting nor kotlin-reflect on Java inner classes, the release changes little.
Source: Kotlin 2.4.21 release on GitHub, 8 October 2026 — https://github.com/JetBrains/kotlin/releases/tag/v2.4.21 ; issue tracker entries, e.g. https://youtrack.jetbrains.com/issue/KT-89220 and https://youtrack.jetbrains.com/issue/KT-89280