A substantial feature and compatibility release for operators, with changed defaults and interfaces alongside correctness and performance improvements. It also includes identified security fixes and refreshes a broad set of dependencies.
Action needed (2)
securityhighThe CVE-2026-15809
/etc/passwdinjection fixCRI-O fixes CVE-2026-15809, which allowed a bypass of the CVE-2022-4318 fix and
/etc/passwdinjection through newline characters in theHOMEenvironment variable.securityhighThe Go toolchain, updated to 1.26.4
The Go toolchain is updated to 1.26.4 to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507.
Check if affected (4)
breakingThe
insecure_registriesoption and--insecure-registryflag, removedApplies if you configure
insecure_registriesor use--insecure-registry.breakingThe
container_level_enableddefault, changed tocheckpoint_onlyApplies if you do not configure
container_level_enabled.breakingThe gRPC message size defaults, reduced to 16 MiB
Applies if
grpc_max_send_msg_sizeorgrpc_max_recv_msg_sizeis not configured.- + 1 more on the release page