RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jan 2026Clear ×
Longhornv1.11.0Storage & DataJan 29, 2026

A substantial feature and maintenance release with V2 Data Engine changes, new capabilities, dependency updates, numerous fixes, and hotfix image replacements. It also deprecates V2 Backing Image functionality and includes a fix for an SPDK v25.05 CVE issue without a disclosed advisory identifier.

Action needed (1)

  • securityThe SPDK v25.05 CVE issue fix

    The CVE issue in SPDK v25.05 is fixed in this release.

Check if affected (7)

  • breakingThe longhornio/longhorn-instance-manager:v1.11.0 image replacement

    Applies if you use longhornio/longhorn-instance-manager:v1.11.0.

  • breakingThe longhornio/longhorn-manager:v1.11.0 image replacement

    Applies if you use longhornio/longhorn-manager:v1.11.0.

  • breakingBackupstore-related settings removal

    Applies if you configure backupstore related settings.

  • + 4 more on the release page

Plan ahead (2)

  • deprecatedBacking Image for the V2 Data Engine deprecationremoval planned in v1.12.0

    Applies if you use Backing Image and the V2 Data Engine.

  • deprecatedV2 Backing Image Feature deprecation

    Applies if you use the V2 Backing Image Feature.

Source
OpenFGAv1.11.3SecurityJan 28, 2026

This release adds configuration and observability capabilities while changing throttling and metric behavior. It also fixes correctness defects, including a described improper policy enforcement issue.

Action needed (2)

  • securitymediumThe CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9 policy enforcement fix

    The release fixes improper policy enforcement associated with CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9.

  • breakingThe custom grpc_code metric label, removed

    The custom grpc_prometheus fork is replaced with go-grpc-middleware's provider, and the custom grpc_code label is removed from the metric.

Source
Kyvernov1.15.3SecurityJan 27, 2026

A maintenance release with security-related fixes for the Go toolchain and cross-namespace access through apiCall. It also contains ordinary defect fixes and capability or behavior changes.

Action needed (1)

  • securityThe go version update for standard library CVEs

    The go version is updated to fix standard library CVEs in this release.

Check if affected (1)

  • securityCross-namespace access through apiCall prevented

    Applies if you use apiCall.

Source
Keycloak26.5.2SecurityJan 23, 2026

Keycloak 26.5.2 is a maintenance release with security fixes alongside ordinary bug fixes and enhancements. The security updates affect third-party dependencies and Keycloak's token issuance logic.

Action needed (3)

  • securitymediumCVE-2025-67735 in netty-codec-http

    CVE-2025-67735 addresses request smuggling via CRLF injection in netty-codec-http. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-66560 in io.quarkus/quarkus-rest

    CVE-2025-66560 addresses the Quarkus REST worker thread exhaustion vulnerability in io.quarkus/quarkus-rest. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-14559 in keycloak-services

    CVE-2025-14559 addresses a business logic flaw in keycloak-services that allowed unauthorized token issuance for disabled users. The fix ships in Keycloak 26.5.2.

Source
Helmv3.20.0Kubernetes CoreJan 21, 2026

A maintenance release with dependency and toolchain updates, several defect corrections, and a new repository timeout flag. The pkg/registry login option for passing TLS configuration in memory has been removed.

Action needed (1)

  • breakingThe pkg/registry in-memory TLS configuration login option, removed

    The pkg/registry login option for passing TLS configuration in memory is reverted and does not ship in this release.

Source
hamiv2.8.0AI & MLJan 20, 2026

Release v2.8.0 adds capabilities and metrics, corrects multiple defects, and updates dependencies. The nvidia-mig-parted upgrade addresses security issues.

Action needed (1)

  • securityThe nvidia-mig-parted dependency, upgraded to v0.12.2

    HAMi v2.8.0 upgrades the nvidia-mig-parted dependency to v0.12.2 to address security issues.

Source
CoreDNSv1.14.1Kubernetes CoreJan 16, 2026

A security-focused maintenance release addresses disclosed Go vulnerabilities and improves proxy connection-pool performance. It also adds the forward plugin's max_idle_conns parameter, which defaults to 0 for an unbounded pool.

Action needed (1)

  • securityhighCVE-2025-68119 fix

    The release also addresses CVE-2025-68119, which affects the stated Go versions.

Check if affected (1)

  • securitycriticalGo security vulnerability fixes

    Applicability is not stated in the release notes.

Source
Ciliumv1.18.6Networking & MessagingJan 13, 2026

A maintenance release with fixes for networking, policy, proxy, gateway API, and endpoint handling, plus dependency, image, and OCI publishing updates. The Cilium Preflight check no longer includes Envoy Configmaps.

Action needed (1)

  • breakingCilium Preflight check no longer includes Envoy Configmaps

    The Cilium Preflight check no longer includes Envoy Configmaps. This change ships in v1.18.6.

Source
Envoyv1.37.0Networking & MessagingJan 13, 2026

This release adds dynamic-module, filter, routing, observability, and certificate capabilities, along with fixes and performance improvements across HTTP, networking, and protocol handling. It also changes HTTP reset behavior, removes runtime guards and legacy code paths, and deprecates the OpenTelemetry access log common_config field.

Action needed (1)

  • breakingRuntime guards and legacy code paths removed

    Multiple runtime guards and legacy code paths are removed in this release.

Check if affected (2)

  • breakingDefault HTTP reset code changed

    Applicability is not stated in the release notes.

  • breakingDefault upstream protocol error reset handling changed

    Applicability is not stated in the release notes.

Plan ahead (1)

  • deprecatedOpenTelemetry access log common_config field deprecated

    Applies if you configure common_config.

Source
CoreDNSv1.14.0Kubernetes CoreJan 8, 2026

A maintenance release with a new regex length constraint, correctness fixes, and plugin capability and behavior changes. It does not disclose a security advisory or explicitly exploitable vulnerability.

Action needed (1)

  • breakingThe core regex length limit

    core adds a length limit for regular expressions.

Source
Prometheusv3.9.0ObservabilityJan 7, 2026

This release updates histogram collection and TSDB behavior while adding capabilities across the API, PromQL, storage, and UI. It also includes fixes for query handling, storage validation, receivers, and interface behavior.

Action needed (1)

  • breakingA 10,000-set limit for the TSDB status endpoint

    The TSDB status endpoint now limits responses to a maximum of 10,000 sets of statistics.

Check if affected (1)

  • breakingThe native-histogram feature flag has no effect

    Applies if you set scrape_native_histograms to collect Native Histogram samples from exporters.

Source
Browse by month