A security-focused patch release fixes multiple dependency vulnerabilities and an ingress-shim defect. It also updates distroless base images and release-signing procedures.
Action needed (6)
securityhighThe
golang.,org/x/net golang., andorg/x/text golang.versionsorg/x/crypto golang.is updated to v0.58.0,org/x/net golang.to v0.41.0, andorg/x/text golang.to v0.55.0. The updates fix CVE-2026-46600, CVE-2026-56852, and CVE-2026-56854.org/x/crypto securityhighThe
google.version and advisory fixesgolang. org/grpc google.is updated to v1.83.2 to fix CVE-2026-84304, CVE-2026-84445, CVE-2026-84303, GHSA-vp52-pcj8-j9qc, GHSA-2v4p-qf9q-27wj, and GHSA-hrxh-6v49-42gf.golang. org/grpc securityThe
Goversion and standard library security fixesGois updated to 1.26.5 and then 1.26.6. These versions include security fixes for thegocommand and thecrypto/tls,encoding/asn1,encoding/xml,html/template,net,net/http, andnet/urlpackages.securitymediumThe
github.versioncom/google/cel-go github.is updated to v0.30.0 to fix the reported vulnerability GHSA-gcjh-h69q-9w9g.com/google/cel-go securityThe security-scanned Go dependencies
golang.,org/x/mod go., andopentelemetry. io/otel go.are updated to versions flagged by security scanners.etcd. io/etcd/client/pkg/v3 securitymediumThe
software.versionsslmate. com/src/go-pkcs12 software.is updated to v0.7.2 to fix the reported vulnerability GHSA-mpwr-8vm7-h73f.sslmate. com/src/go-pkcs12
