RATATOSKRATATOSK
Sign in

Don't read release notes for 77 CNCF projects.

Alerts only when your stack needs action, and what to do about it.

77 projects · 981 analyses · this week 34 reviewed → 14 alerts

Latest releases

last 24 hoursAll releases →
cert-managerv1.20.4SecurityTodaySep 16, 2026

A security-focused patch release fixes multiple dependency vulnerabilities and an ingress-shim defect. It also updates distroless base images and release-signing procedures.

Action needed (6)

  • securityhighThe golang.org/x/net, golang.org/x/text, and golang.org/x/crypto versions

    golang.org/x/net is updated to v0.58.0, golang.org/x/text to v0.41.0, and golang.org/x/crypto to v0.55.0. The updates fix CVE-2026-46600, CVE-2026-56852, and CVE-2026-56854.

  • securityhighThe google.golang.org/grpc version and advisory fixes

    google.golang.org/grpc is updated to v1.83.2 to fix CVE-2026-84304, CVE-2026-84445, CVE-2026-84303, GHSA-vp52-pcj8-j9qc, GHSA-2v4p-qf9q-27wj, and GHSA-hrxh-6v49-42gf.

  • securityThe Go version and standard library security fixes

    Go is updated to 1.26.5 and then 1.26.6. These versions include security fixes for the go command and the crypto/tls, encoding/asn1, encoding/xml, html/template, net, net/http, and net/url packages.

  • securitymediumThe github.com/google/cel-go version

    github.com/google/cel-go is updated to v0.30.0 to fix the reported vulnerability GHSA-gcjh-h69q-9w9g.

  • securityThe security-scanned Go dependencies

    golang.org/x/mod, go.opentelemetry.io/otel, and go.etcd.io/etcd/client/pkg/v3 are updated to versions flagged by security scanners.

  • securitymediumThe software.sslmate.com/src/go-pkcs12 version

    software.sslmate.com/src/go-pkcs12 is updated to v0.7.2 to fix the reported vulnerability GHSA-mpwr-8vm7-h73f.

Source
containerdapi/v1.12.0Kubernetes CoreTodaySep 16, 2026

A feature and maintenance release adds runtime and API capabilities while updating dependencies. It also deprecates two interfaces, with no disclosed security changes.

Plan ahead (2)

  • deprecatedcontainerd.io/runtime-allow-mounts shim annotation deprecation

  • deprecatedTask API address and version fields in runc options

Source
Keycloak26.7.4SecurityTodaySep 16, 2026

A security-heavy maintenance release with vulnerability fixes, alongside correctness and performance corrections. It also updates the Quarkus dependency.

Action needed (4)

  • securityhighCVE-2026-79651 and unbounded locale caching

    CVE-2026-79651 fixes an unauthenticated denial-of-service issue caused by unbounded locale caching. The fix ships in this release.

  • securityhighCVE-2026-74909 and matrix parameter stripping

    CVE-2026-74909 completes the fix for a percent-encoded semicolon bypass of matrix parameter stripping in PathMatcher. The fix ships in this release.

  • securityhighCVE-2026-17526 and the impersonation role

    CVE-2026-17526 fixes privilege escalation involving the impersonation role impersonating a realm administrator. The fix ships in this release.

  • securitymediumCVE-2026-19607 and username takeover

    CVE-2026-19607 fixes a username takeover issue that could lead to account lockout. The fix ships in this release.

Check if affected (2)

  • securityhighCVE-2026-18212 and SAML Redirect DEFLATE helpers

    Applies if you use SAML Redirect.

  • securityCVE-2026-90997 and stateless replay gate row counts

    Applies if you use MySQL/MariaDB.

Source
Ciliumv1.20.2Networking & MessagingTodaySep 16, 2026

A maintenance release focused on correctness fixes, reliability improvements, dependency updates, and additive configuration and integration capabilities. It contains no disclosed vulnerability details.

Source
Ciliumv1.19.8Networking & MessagingTodaySep 16, 2026

A maintenance release focused on correctness fixes and dependency updates, with a small number of new extension points. It does not introduce broad operator-facing configuration changes.

Action needed (1)

  • breakingRemoval of the Ingress HostFW Policy between RevSNAT and RevDNAT

    The BPF NodePort path removes the Ingress HostFW Policy between RevSNAT and RevDNAT.

Source
Ciliumv1.18.14Networking & MessagingTodaySep 16, 2026

A maintenance release focused on bug fixes, dependency updates, and image refreshes. It also removes a datapath behavior and includes security dependency fixes that may require operator attention.

Action needed (3)

  • securityThe google.golang.org/grpc module, updated to v1.83.1

    The google.golang.org/grpc module is updated to v1.83.1 in this release as a security dependency fix.

  • securityThe google.golang.org/grpc module, updated to v1.83.2

    The google.golang.org/grpc module is updated to v1.83.2 in this release as a security dependency fix.

  • breakingThe Ingress HostFW Policy between RevSNAT and RevDNAT, removed

    The Ingress HostFW Policy between RevSNAT and RevDNAT is removed in this release.

Source