This cri-o release includes a fix for a disclosed security vulnerability alongside runtime behavior, monitoring configuration, metric, and dependency updates. It is most relevant to deployments affected by the HOME environment-variable issue or the related observability and CNI configuration changes.
Action needed (1)
securityhighCVE-2026-15809 HOME environment-variable injection fix
cri-o v1.36.3 fixes CVE-2026-15809. The vulnerability allowed a bypass of the CVE-2022-4318 fix, enabling
/etc/passwdinjection through newline characters in theHOMEenvironment variable.