RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jan 2026Clear ×
OpenFGAv1.11.3SecurityJan 28, 2026

This release adds configuration and observability capabilities while changing throttling and metric behavior. It also fixes correctness defects, including a described improper policy enforcement issue.

Action needed (2)

  • securitymediumThe CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9 policy enforcement fix

    The release fixes improper policy enforcement associated with CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9.

  • breakingThe custom grpc_code metric label, removed

    The custom grpc_prometheus fork is replaced with go-grpc-middleware's provider, and the custom grpc_code label is removed from the metric.

Source
Kyvernov1.15.3SecurityJan 27, 2026

A maintenance release with security-related fixes for the Go toolchain and cross-namespace access through apiCall. It also contains ordinary defect fixes and capability or behavior changes.

Action needed (1)

  • securityThe go version update for standard library CVEs

    The go version is updated to fix standard library CVEs in this release.

Check if affected (1)

  • securityCross-namespace access through apiCall prevented

    Applies if you use apiCall.

Source
Keycloak26.5.2SecurityJan 23, 2026

Keycloak 26.5.2 is a maintenance release with security fixes alongside ordinary bug fixes and enhancements. The security updates affect third-party dependencies and Keycloak's token issuance logic.

Action needed (3)

  • securitymediumCVE-2025-67735 in netty-codec-http

    CVE-2025-67735 addresses request smuggling via CRLF injection in netty-codec-http. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-66560 in io.quarkus/quarkus-rest

    CVE-2025-66560 addresses the Quarkus REST worker thread exhaustion vulnerability in io.quarkus/quarkus-rest. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-14559 in keycloak-services

    CVE-2025-14559 addresses a business logic flaw in keycloak-services that allowed unauthorized token issuance for disabled users. The fix ships in Keycloak 26.5.2.

Source
Browse by month