This release adds Helm, API, solver, and feature-gate capabilities while changing defaults and accepted behavior. It also corrects bugs and includes security fixes in the cert-manager controller and Go.
Action needed (2)
securityhigh
Gov1.update for CVE-2025-61727 and CVE-2025-6172925. 5 Gois updated tov1.to fix CVE-2025-61727 and CVE-2025-61729.25. 5 breakingIssuer reference kind and group defaults, reverted
The default issuer reference kind and group values are reverted to the behavior before 0.19.0.
Check if affected (4)
securityPotential
cert-manager controllerpanic from cached DNS responsesApplicability is not stated in the release notes.
The
cert-manager controllerno longer risks a panic when it caches a DNS response in an unexpected order. An attacker who can modify DNS responses or control the DNS server could otherwise cause a denial of service.breakingThe
OtherNamesfeature, enabled by defaultApplies if you use the
OtherNamesfeature.The
OtherNamesfeature is promoted to Beta and enabled by default.breakingDefault container user and group IDs
Applies if you do not configure the default container user (UID) or do not configure the default container group (GID).
The default container user UID changes from 1000 to 65532, and the default container group GID changes from 0 to 65532.
- + 1 more on the release page