CRI-O
v1.36.3Kubernetes CoreAug 4, 2026
CRI-O v1.36.3 is a security patch fixing a bypass (CVE-2026-15809) of an earlier /etc/passwd injection defense, plus a restoration of non-UTF8 env var support and two new CNI status monitoring config options.
security/etc/passwd injection bypass fixed
A bypass of CVE-2022-4318 allowed /etc/passwd injection via newline characters in the HOME environment variable (CVE-2026-15809). The fix ships in v1.36.3.
Key changes (4)
- Security: /etc/passwd injection bypass (CVE-2026-15809) fixed
- Non-UTF8 environment variable handling restored to pre-1.34 behavior
- CRI metrics now include namespace, pod, and container labels
- CNI status monitoring config additions: enable_cni_status_monitoring and cni_status_grace_period
Add CRI-O to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.